Renovix migrates code that runs the financial, healthcare, and government systems of record. Security is not a tier — it is the architecture.
Audited annually by a Big-4 firm. Report available under NDA.
Certified. Includes ISO 27017 (cloud) and 27018 (PII) annexes.
BAA available. PHI handled only in HIPAA-eligible deployments.
In process. SSP and POA&M available to authorized agencies.
AI management system certification — first AI startup to pursue it.
Compliant when cardholder data is in scope. RoC available.
EU SCCs, UK IDTA, and EU AI Act conformity documentation.
Full data subject rights and California privacy compliance.
Per-tenant compute pools with no shared model state between customers.
Top-tier customers run on schema-isolated Postgres with per-tenant KMS keys.
Customer data never enters another customer's model. BYOM also supported.
Enterprise customers can run Renovix in their own AWS, Azure, or GCP account.
Bring your own KMS-managed keys; rotate without involving Renovix.
For classified workloads, a hardened single-tenant appliance is available.
Customer code is processed only for the purpose of the migration. It is never used to train models for other customers. It is never used to train models without contractual permission. Period.
Inputs are encrypted in transit (TLS 1.3) and at rest (AES-256). PII is redacted at ingest using a layered detector. Inference runs in tenant-isolated compute pools.
// Data flow guarantees { "in_transit": "TLS_1.3 + mTLS", "at_rest": "AES-256 (BYOK)", "cross_tenant": "prohibited", "model_training": "contractual opt-in only", "retention": "customer-defined", "deletion": "30-day verified purge" }
Input sanitization, tool allow-lists, and output validators on every agent run.
Every tool runs in a sandboxed execution environment with per-tool authz.
The verifier model is architecturally and statistically independent of the executor.
Every output ships with a calibrated confidence score and abstains when unsure.
Golden datasets and adversarial probes run on every model release.
Continuous red-team exercises against the agent system; quarterly external pen-test.
Every agent action — every tool call, every code change, every approval — is captured in an immutable append-only log. Logs can be exported to your SIEM (Splunk, Sumo, Datadog) in real time, or pulled into Snowflake or BigQuery for long-term retention.
// Audit event { "ts": "2026-05-18T14:08:21Z", "actor": "agent.translator.cobol", "action": "translate.module", "input_hash": "sha256:91a4...", "output_hash": "sha256:c3d8...", "confidence": 0.984, "reviewer": "sme.aroy@northwind", "verdict": "APPROVED" }
Default. Logical isolation, US or EU region.
Dedicated infrastructure for compliance-sensitive workloads.
Runs in your AWS, Azure, or GCP account. Control plane managed by Renovix.
Hardened appliance for classified or fully isolated environments.
Public bug bounty program with payouts up to $25,000 for critical findings. Safe harbor for good-faith researchers.
Email security@renovix.com with PGP. Median response time: under 24 hours. Coordinated disclosure encouraged.
Procurement-ready security pack available under NDA in two business days.
Request security pack