Default deny
An empty policy grants nothing. Sources, tables, rows, columns, operators, writes, and egress budgets are explicitly scoped for each agent.
Oliver separates deterministic policy enforcement from the reasoning layer agents use to improve. Every agent receives its own policy, every query is constrained before execution, and every action can be attributed and reviewed.
An empty policy grants nothing. Sources, tables, rows, columns, operators, writes, and egress budgets are explicitly scoped for each agent.
Agent Flight Control rewrites the query to include the permitted scope instead of relying on a blocklist to recognize every unsafe query an agent might invent.
Allowed and denied statements are recorded with the rewrite, mask, or clamp applied. Reasoning artifacts and operator history can be preserved separately for review.
Agents may learn from tenant‑scoped reasoning history, but the policy layer does not self‑modify. Policy changes remain subject to the customer’s approval process.
Oliver can run inside your VPC so data, network controls, and keys remain within your perimeter, or as a managed deployment operated with Oliver. Identity integration, encryption requirements, audit retention, data residency, incident response, and regulatory obligations are documented and scoped for each production deployment.
Oliver does not claim a certification merely because a customer requests it. Current controls and required obligations are reviewed directly during security evaluation.
If you believe you have found a security issue in OliverDB, the console, or this website, email info@oliverdb.ai with what you found, how to reproduce it, and how to reach you. We acknowledge reports within two business days, keep you informed while we fix the issue, and credit you if you want that. Good-faith research that avoids customer data, service disruption, and public disclosure before a fix is welcome and will not be met with legal action.
Machine-readable contact details are published at /.well-known/security.txt.