Your repo·your cloud·your keys

Security by ownership.Your perimeter, not ours.

Most AI vendors ask you to trust their infrastructure with your data. We build inside yours. The code ships to your GitHub, the agents run in your cloud account, and nothing leaves a perimeter you already control.

ISO 27001inherited from your cloud
SOC 2 Type IIinherited from your cloud
GDPRready
SSO / SAMLper build

Enterprise-level security. Without handing anyone your data.

01

Isolation by design

Every agent runs sandboxed, with scoped permissions per integration. The Resolution Agent can process a refund; it cannot touch your ad account. Blast radius is defined before deploy, not discovered after.

02

Full transparency

No black box. The code is in your repo, readable by your team, auditable line by line. Every agent action writes to an immutable log: who, what, when, why.

03

Data sovereignty

Your data never moves into Digital Horizon infrastructure, because Digital Horizon infrastructure doesn’t exist in your build. Orders, tickets and customer records stay in your cloud, your region, your jurisdiction.

04

Operator-defined rails

You set the thresholds: which actions run autonomous, which need a human signature, which are off-limits entirely. Approvals route to Slack or Telegram. Rails are config, not promises.

Runs on
AnthropicAWSGoogle CloudGitHub

Provable by architecture. Not by promise.

0

Third parties holding your code or your customer data

0%

Of agent actions written to the audit trail

0

Cloud account everything runs in. Yours.

We build systems that act on your customers and your money. That’s powerful to deploy and dangerous to deploy wrong, so every build ships with sandboxing, rails and logs as defaults, not add-ons. Security isn’t a tier. It’s the floor.

A Digital Horizon build is custom infrastructure, so its security posture is documented per build, not per platform. Every engagement ships with an architecture document, a permissions map per agent, a data-flow diagram showing exactly what touches what, and runbooks for incident handling.

The documents below describe the standards every build starts from. Your build’s specifics live in your handoff pack.

Standards every build starts from.

Request access to documents →

GDPR

Compliant by operation

Digital Horizon operates under GDPR. Builds for EU brands keep customer data in EU regions of your cloud account. Data processing agreements are signed per engagement.

ISO 27001 / SOC 2

Inherited from your cloud

Your build runs on AWS or GCP infrastructure that holds ISO 27001 and SOC 2 Type II. Because the system lives in your account, those certifications cover your deployment directly. No vendor in between to audit.

Anthropic Enterprise Terms

Contractual

All inference runs through the Anthropic API under commercial terms: inputs and outputs are not used for model training. Model and data-handling documentation available on request.

Per-build Security Spec

Per engagement

Every build is delivered against a written security spec: agent permissions, approval thresholds, data flows and incident procedures, signed by both parties before deploy.

Controls. Continuously, per build.

3

Change Management

  • Every change ships as a reviewed pull request in your repo
  • Staged deploys: dev → staging → production
  • Rollback procedures documented in runbooks
3

Availability

  • Runs on your cloud’s availability zones and SLAs
  • Health checks and dead-letter queues per agent
  • Failure alerts route to your Slack within minutes
3

Access Security

  • Least-privilege credentials per agent, per integration
  • No standing Digital Horizon access after handoff. Granted and revocable by you
  • Key rotation procedures in the handoff pack
3

Confidentiality

  • Customer data never leaves your cloud account
  • Secrets managed in your cloud’s secret manager, never in code
  • No training on your data at any layer
2

Vulnerability Management

  • Dependency scanning in the repo’s CI pipeline
  • Patch procedures documented for your team or covered under maintenance
3

Incident Response

  • Per-build incident runbook: detect, contain, roll back, report
  • Kill switch per agent in Mission Control: one command, agent paused
  • Post-incident log review with full audit trail
2

Risk Assessment

  • Pre-deploy audit maps data flows and failure modes before any code runs
  • Approval thresholds set per action class during the build spec
2

Network Security

  • Agents communicate over your cloud’s private networking where available
  • All external calls over TLS; API keys scoped and rotated
2

Organizational

  • Two named partners accountable per build, no anonymous offshore handoff
  • Build-spec signed by both parties before development starts
1

Physical Security

  • Inherited from your cloud provider’s data centers (ISO 27001 / SOC 2 scope)

A short list. Because the architecture is the privacy policy.

Most vendors need a long subprocessor table. Ours is short by design.

PartyRoleYour data exposure
Your cloud account (AWS / GCP)Hosting, storage, networkingEverything: under your contract, your keys, your region
Anthropic APIModel inferencePrompt context per request. Not used for training. Enterprise terms.
GitHub (your org)Code repositoryCode only. No customer data. Repo owned by you.
Your existing stackSource systems (Shopify, Klaviyo, Gorgias…)Already yours. Agents connect with scoped credentials you issue

Digital Horizon itself holds: your contact details and the build documentation. That’s the list.

On data and security. Answered plainly.

Anything else? Contact the security team. A person answers, usually the same day.

No. Inference runs through the Anthropic API under commercial terms: inputs and outputs are never used for training, at any layer. Everything else stays in your cloud and never reaches a training set.

Security isn’t a tier. It’s the floor.

Every build ships with sandboxing, rails and logs as defaults, not add-ons.

Contact the security team
Last updated: June 2026