Security

Trust agents without trusting them blindly.

Oliver separates deterministic policy enforcement from the reasoning layer agents use to improve. Every agent receives its own policy, every query is constrained before execution, and every action can be attributed and reviewed.

Architecture

Control at the boundary. Evidence after every run.

Policy

Default deny

An empty policy grants nothing. Sources, tables, rows, columns, operators, writes, and egress budgets are explicitly scoped for each agent.

Enforcement

Compiled into the query

Agent Flight Control rewrites the query to include the permitted scope instead of relying on a blocklist to recognize every unsafe query an agent might invent.

Audit

Every action attributable

Allowed and denied statements are recorded with the rewrite, mask, or clamp applied. Reasoning artifacts and operator history can be preserved separately for review.

Change control

Learning cannot move the fence

Agents may learn from tenant‑scoped reasoning history, but the policy layer does not self‑modify. Policy changes remain subject to the customer’s approval process.

Deployment

Your boundary, or ours.

Oliver can run inside your VPC so data, network controls, and keys remain within your perimeter, or as a managed deployment operated with Oliver. Identity integration, encryption requirements, audit retention, data residency, incident response, and regulatory obligations are documented and scoped for each production deployment.

Oliver does not claim a certification merely because a customer requests it. Current controls and required obligations are reviewed directly during security evaluation.

Responsible disclosure

Found something? Tell us first.

If you believe you have found a security issue in OliverDB, the console, or this website, email info@oliverdb.ai with what you found, how to reproduce it, and how to reach you. We acknowledge reports within two business days, keep you informed while we fix the issue, and credit you if you want that. Good-faith research that avoids customer data, service disruption, and public disclosure before a fix is welcome and will not be met with legal action.

Machine-readable contact details are published at /.well-known/security.txt.

Bring your security team into the evaluation.