This Security Policy describes the controls CloudsCockpit Inc. applies to the ActionBoard.ai platform and the responsibilities shared with you. It supplements, and should be read alongside, the Terms of Service. Capitalized terms have the meanings given there.
01 Shared Responsibility Model
Security on ActionBoard.ai is a partnership. CloudsCockpit Inc. secures the platform, control plane, and provisioned pods; you secure the identities, keys, and content you manage inside your pods.
CloudsCockpit We secure
- Underlying platform infrastructure & Control Plane
- Dedicated pod provisioning & isolation
- System-level security updates & patching
- Global system uptime & monitoring
Customer You secure
- Role-based access controls (IAM/SSO) in your pods
- Local encryption keys & credential protection
- Workspace configuration integrity
- Privacy-law & institutional compliance of your data
02 Infrastructure & Hosting
- Validated providers only AI model inferences must run exclusively on infrastructure providers validated and approved by CloudsCockpit Inc. Unvalidated third-party hosting is prohibited and is not covered by this policy.
- ISO-certified for AIOps Model performance is measured and recognized only when operating on a CloudsCockpit-validated, ISO-certified provider for AIOps.
- Managed baseline layer ActionBoard provides a baseline optimal infrastructure layer with an integrated AIOps interface. Modifying or circumventing this layer without explicit written consent is prohibited and voids the applicable security guarantees.
- Pod isolation Dedicated pods are provisioned with tenant isolation at the control-plane boundary, so one lab’s workloads and knowledge base cannot reach another’s.
03 Encryption & Key Management
- Encrypted at rest & in transit All user data is fully encrypted. Data in transit is protected with TLS; data at rest is encrypted on validated infrastructure.
- KMS-managed private keys Encryption keys are managed via AWS and Cloudflare KMS (Key Management Service). Customers may additionally manage local encryption keys for data they hold in local or hybrid pods.
- Credential handling Platform secrets and integration credentials are stored in managed secret stores, never in plaintext configuration or audit logs.
04 Data Ownership & Sharing
CloudsCockpit and its suite of services ensure that the user owns 100% of their own data. We process it only to operate the Platform on your behalf.
- Sponsor lab telemetry Where a sponsor lab’s data-sharing setting applies, only anonymised signals may be shared — prompts, completions, tool-call latencies, and error traces. Personally identifiable information is never shared.
- Your choice is the source of truth A lab’s data-sharing field plus your deploy-time choice determine what, if anything, leaves your pod. Opting out of optional sharing is always honored.
- Knowledge base boundaries KB collections are scoped to their owning pod and are not used to train shared models without a formal written agreement.
05 Identity & Access Control
- Role-based access Lab administrators manage IAM/SSO and role-based access controls within their pods. Access is least-privilege by default.
- Pilot accounts During the current pilot, access is provisioned per lab or per enterprise agreement. Enterprise SSO/SCIM is available under the applicable enterprise lab specification.
- Delegated actions Action Assist delegation is scoped to your public handle and honors the permissions of the delegating account; it never bypasses your pod’s access controls.
06 Multi-Agent Safety — AgentFormation & the Yellow Lion
The AgentFormation 5-Lion orchestration system runs every workload through a stewardship layer before it acts on the outside world.
- Yellow Lion policy gate The Yellow Lion is the steward of every outbound action. Even when a user disables the Yellow Lion’s autonomous override, its policy gates remain on.
- Consent before new servers Registering any new MCP gateway or federated server requires an explicit consent grant, recorded to the audit stream.
No full bypass. The Platform does not provide any control that lets a user fully disable the Yellow Lion’s guardrails. Attempting to interfere with multi-agent orchestration is a breach of the Terms of Service.
07 Audit, Compliance & Proof-of-Thought
- Immutable audit stream Every veto, deploy, and consent grant is written to a write-only audit stream owned by the Yellow Lion.
- Proof-of-Thought Audit entries are immutable and Merkle-attested under the Proof-of-Thought specification, so an action history can be independently verified and defended.
- Self-service reports A full infrastructure audit report is available to you at any time within ActionBoard settings under the “Audit and Compliance” section.
Tampering with or bypassing Proof-of-Thought logs results in immediate termination of access under the Terms of Service.
08 Bank-Grade Plans, SLA & Uptime
- Bank-grade tiers Customers requiring bank-grade protection infrastructure purchase the Pro Max or Business Max plan.
- 24/7 support & SLA These plans include 24/7 dedicated support and a formal Service Level Agreement covering availability and response times.
- Uptime CloudsCockpit Inc. maintains global system uptime and monitoring for the platform and provisioned pods.
09 Incident Response
We monitor the control plane and provisioned pods continuously. In the event of a confirmed security incident affecting your data, CloudsCockpit Inc. will investigate, contain, and notify affected lab administrators in accordance with the applicable Service Level Agreement and law. Under the Shared Responsibility Model, incidents originating in user-managed configurations remain the customer’s responsibility as described in the Terms of Service.
10 Responsible Disclosure
We welcome reports from security researchers. If you believe you have found a vulnerability, please disclose it privately and give us a reasonable window to remediate before any public disclosure. Do not access data that is not yours or degrade service for other users while testing.
Report a security issue
CloudsCockpit Inc. / ActionBoard.ai — Security & Compliance
