RaksHex Security
Private beta · aligned with the Trust Center. Reviewers should start at /trust and email security@rakshex.in.
RaksHex is an Agent Firewall: runtime authorization for autonomous AI actions. This page describes controls that exist in the current product and in docs/SECURITY.md. It is not a certification, an audit report, or a data-residency catalog. Where a control is not yet in the private-beta cut, it is omitted rather than described as shipped.
We protect against the following categories when traffic is evaluated through the Agent Firewall and related governance paths:
Semantic actions are authorised against delegated authority before they run. A child authority cannot exceed its parent. A DENY is enforced at credential mediation, not only as an advisory log line.
Gateway and scanning paths inspect prompts and tool calls for injection and unsafe output patterns. Coverage depends on deployment configuration.
Workspace credentials are encrypted before storage. List APIs return masked metadata and fingerprints. Discovery is designed to send masked metadata rather than secret values.
Kill switches, budgets, and tool allowlists can stop further calls when a policy trips. Response time depends on deployment topology.
RaksHex maps product controls to common frameworks (including OWASP, NIST AI RMF, ISO, SOC 2, GDPR, DPDP, and the EU AI Act) and can export that evidence. We do not claim a certification or independent audit until that assessment is complete and published. Dashboard scores and PDFs, where present, are mapping artifacts for your own audit workflow — not an attestation that RaksHex is SOC 2, PCI DSS, OWASP, or ISO certified.
Data-processing terms, subprocessors, and transfer language live in the Legal Center. Residency, private relay, and self-hosted deployment are agreed on an enterprise Order Form when they apply; they are not marketed here as a standard product option.
Report suspected vulnerabilities, privacy requests, legal notices, or security incidents to security@rakshex.in. Do not send provider keys, passwords, or sensitive evidence by email.
Verifiable commitments are on the Trust Center. This page will not list a badge, audit-in-progress status, or residency region until that evidence is published.