Trust Center
Everything your risk team needs. One URL.
How Mault deploys, enforces, records, and proves, written for the people who have to sign off. Send this page to security review.
Deployment & data
Your environment. Nothing leaves it.
Fully local
Self-hosted, on-premises, or in your own VPC. Air-gapped deployments supported.
Zero telemetry
No data, code, or metadata leaves your environment. The audit record is yours and stays with you.
No vendor lock in the loop
Mault is IDE- and agent-agnostic. Swap agents or models without changing your governance.
Enforcement architecture
Deterministic. No LLM in the enforcement path.
Four checkpoints
Write time, commit time, CI, and merge time. Each catches what the one before might miss. No single point of failure.
Same input, same decision
Rules evaluate mechanically. No model makes a probabilistic call about whether your code is allowed to ship.
Fails closed
In cross-workstation mode, if zone claims can’t be verified across machines, work is blocked rather than allowed.
Audit & attribution
A record built to be challenged.
Signed and chain-linked
Every governance decision is written as an audit event, Ed25519-signed with a per-session key and chain-linked to the previous event.
Sealed sessions
The session key is destroyed at seal, so the past cannot be re-signed. Change one byte and the chain breaks.
100% attribution
Every action reportable by workstation, agent, session, and machine, verifiable offline by someone who doesn’t trust you.
what one record actually contains · .mault/audit-events/*.jsonl
ts 2026-07-08T14:23:07.412Z
tool Write · src/auth/session.ts
role worker
sessionId s_9f2c…e41a auditId a_0117…8c3d
validators zone-boundary-gate · pre-write-test-gate · role-write-gate
status ALLOW workstation ws_7f2a-03
Allows recorded, not just denies.
Proof the gates were running the whole time, not only when something blocked.
Session identity is single-use.
A short-lived token bound to a role and to the specific agent expected to consume it.
Receipts, enforced.
A session can’t stop until its role writes step-complete.json. Bootstrap logs catch runtime mismatches at start.
Representative slice. The full inventory also covers session state, zone and budget snapshots, delegation maps, and review configuration.
File-access assurance
Tamper-evident file enforcement.
Tier
What it does
Defends against
File locking
tamper-evident
tamper-evident
Enforcement lives below where an attacker or the extension operates, the deepest
tier in the stack.
the privileged insider
OS-level
tamper-evident · default
tamper-evident · default
Admin-controlled, centralized config. Fails loud if tampered, fully logged.
the ordinary insider
Tamper logging
always on
always on
Every tamper attempt recorded in the signed chain. Nothing happens quietly.
the careless
Breach-time enforcement: halt agent activity at the machine when something is wrong. Built for containment, beyond what frameworks like FINOS specify.
Compliance
Packaged for the frameworks your auditors use.
Signed, tamper-evident records packaged for audit. Meets 100% of in-scope FINOS controls; the remainder are cloud-runtime controls that don’t apply to a fully local deployment.
SOC 2
GDPR
PCI
ISO 27001
EU AI Act
FINOS
Multiple patents pending
Put us in front of your risk team.
Security questionnaires, architecture review, or a pilot scoped to one repo. We’ll meet your process where it is.