Security posture
Autonomous ops that a CISO can sign off on.
Merchanaut gives the agents autonomy on the floor — inventory, pricing, restock, orders, refunds — and pays for that autonomy with a governance surface that meets mid-market IT and security where they already live: guardrails before every write, an audit trail bound to evidence, encryption in transit and at rest, role-based access gated by the admin plugin, a 24/7 watch over every running agent, and a procurement-ready packet waiting when your security team asks.
1 — Guardrails
PAUSE, audit, and write boundaries on every agent move.
The agents never get the keys directly. Every mutating action — a price change, a restock order, a refund, a supplier PO — crosses a guardrail first. The guardrail fails closed, not log-and-continue, and it is the same gate on every tier. The policies that drive it live on the dashboard — your team reads them, edits them, and audits the changes without an engineer in the loop.
- A gate every agent must cross before mutating catalog, pricing, orders, or supplier POs — fail-closed, not log-and-continue.
- Write boundaries keyed to the role of the calling agent and the user on whose behalf it acts — no agent writes outside its tier.
- A Bob-Test pre-flight that repeats its own deterministic check on every pricing move — the policy surface is on the dashboard.
2 — Audit trail
Every decision linked to evidence.
The audit trail is not a log file. Each entry names the agent, the policy version that approved the move, the snapshot it acted on, and the evidence pack it cited. The timeline is replayable — input the same snapshot and the same policy produces the same decision, so a security reviewer can rerun an incident end-to-end without trusting the agent's recollection.
- Every agent decision binds to the snapshot, the evidence pack, and the policy version that approved it.
- The timeline on the audit page is replayable — same inputs reproduce the same decision, signed and timestamped.
- Audit rows are exportable as JSON for downstream SIEM, GRC, or retention storage.
3 — Data handling
Encryption posture, role-based access — no shared passwords.
Every byte that crosses Merchanaut is encrypted in transit and encrypted at rest. Access is scoped per user with the better-auth admin plugin — admin roles gate the settings surface, agent roles gate the write surface, both gates are enforced on the same /api layer the platform ships with. There is no shared admin account, no shared password, and no admin cookie written outside the auth module.
Sovereign deployments isolate per-tenant keys and per-tenant storage before they reach the agent — a regulated retailer runs the same fleet on a private substrate, not a multi-tenant shard.
- Encryption in transit: TLS 1.3 across every agent↔source and dashboard↔agent hop. HSTS on the marketing and dashboard origins.
- Encryption at rest: managed application-layer encryption for snapshot, evidence, and decision stores; per-tenant key isolation on sovereign deployments.
- Role-based access: scoped to per-user data with the better-auth admin plugin — admins gate by role, agents gate by tier, both gates enforced on the same /api surface.
- Secrets: every third-party credential is short-lived, injected at deploy, never pasted into a config file.
4 — Operational assurance
A 24/7 watch — and the edges where the agent refuses to act.
Autonomy is paid for with attention. The agent-watch layer monitors every running agent — stall, drift, anomalous retries — and escalates to the on-call before any of it reaches a customer. There are also the no-action zones: the catalog edges, the supplier blacklists, the regulated categories, and the pricing floors where the agent is forbidden to act and a named human owns the decision instead.
The same watch runs an anomaly review against the audit trail each week — slow-burn patterns that pass guardrails but should not tick up the human queue anyway.
- A 24/7 agent-watch layer watches every running agent — stall, drift, and out-of-band retries page the on-call before they reach a customer.
- No-action zones: the shelf edges and supplier edges where the agent refuses to act and escalates to a named human — pricing floors, regulated categories, and supplier blacklists.
- Anomaly review: weekly walk of the audit trail for slow-burn patterns that pass guardrails but should not — pricing drift, supplier reply cadence, refund clustering.
5 — Procurement-ready
The packet your IT and security teams ask for.
Mid-market IT and security teams get a packet they can run review against without an in-person meeting. Every item below is in the procurement packet — sent over the contact form on request, with the actual documents and signed artefacts to follow.
SOC 2 readiness
The control inventory and evidence map are ready for a Type II review — security, availability, and confidentiality criteria covered.
Data residency
Default to US/EU regional deployments; sovereign instances available for retailers with in-country data-residency obligations.
DPA + sub-processor list
A signed DPA on request and a current sub-processor list with a 30-day notice window for changes — the same list you sign for the platform contract.
Breach-notice SLA
Notification within 72 hours of confirmed incident, with the affected scope, data classes, and remediation timeline in the same message.
Pen-test cadence
Annual third-party penetration test of the agent surface and the dashboard — full report under NDA on request.
Access reviews
Quarterly reviews of admin-role grants via the admin plugin — every active admin session is attributable to a named user.
Ready when your security team is
Request the security packet — answers in one thread, not a vendor chase.
The same engineer who builds the guardrails takes the call. The procurement packet, the SOC 2 readiness control map, the sub-processor list, the DPA — whichever ones your team is ready to read first, that is what we send first.