Trust center

Security and compliance

Tensor Dynamics Watch is designed around private deployment, least privilege, and auditable operations. This page separates implemented controls from certifications still in progress.

Last updated: July 11, 2026

Implemented controls: documented · Third-party certifications: not currently claimed

Deployment and data boundaries

  • Inference can run entirely on customer-controlled hardware.
  • Events, snapshots, and audit records can remain in a customer-controlled data directory.
  • Cloud models and external integrations are optional; administrators choose which services to enable.

Access control

  • Command roles are separated into viewer, operator, and admin.
  • The MCP endpoint uses bearer-token authentication; command tools are disabled by default.
  • High-impact actions should require human approval and run through existing site-control systems.

Auditability

  • Status transitions are written to an append-only event log.
  • Critical events can retain timestamped image evidence.
  • Agent tool calls, notifications, and operator actions can preserve source and time context.

Secure development

  • Sensitive configuration is supplied through environment variables and should not be committed to source control.
  • External alert webhooks support HMAC verification.
  • Inference, notification, and agent-tool failures are isolated from the primary monitoring loop.

Certification status

We do not currently claim SOC 2, ISO 27001, HIPAA, or other third-party certification. If your procurement process requires specific controls, a DPA, data residency, or a security questionnaire, contact us for a deployment review.

Report a security issue

Do not disclose vulnerabilities in a public issue. Send reproduction steps, impact, and contact details to security@tensordynamics.org.