Trust center
Security and compliance
Tensor Dynamics Watch is designed around private deployment, least privilege, and auditable operations. This page separates implemented controls from certifications still in progress.
Last updated: July 11, 2026
Implemented controls: documented · Third-party certifications: not currently claimed
Deployment and data boundaries
- Inference can run entirely on customer-controlled hardware.
- Events, snapshots, and audit records can remain in a customer-controlled data directory.
- Cloud models and external integrations are optional; administrators choose which services to enable.
Access control
- Command roles are separated into viewer, operator, and admin.
- The MCP endpoint uses bearer-token authentication; command tools are disabled by default.
- High-impact actions should require human approval and run through existing site-control systems.
Auditability
- Status transitions are written to an append-only event log.
- Critical events can retain timestamped image evidence.
- Agent tool calls, notifications, and operator actions can preserve source and time context.
Secure development
- Sensitive configuration is supplied through environment variables and should not be committed to source control.
- External alert webhooks support HMAC verification.
- Inference, notification, and agent-tool failures are isolated from the primary monitoring loop.
Certification status
We do not currently claim SOC 2, ISO 27001, HIPAA, or other third-party certification. If your procurement process requires specific controls, a DPA, data residency, or a security questionnaire, contact us for a deployment review.
Report a security issue
Do not disclose vulnerabilities in a public issue. Send reproduction steps, impact, and contact details to security@tensordynamics.org.