TekCapitol
Continuous Action Assurance™ · Trust

Security

TekCapitol, Inc. · Continuous Action Assurance™ · Check Write™

Product stance

· Does TekCapitol execute the destination write? No. Your orchestrator or application owns execution after Allow, Pause, or Block.
· What does Check Write™ evaluate? Write Intent metadata and control evidence you (or configured connectors) supply for that action.
· Where can evaluation run? Hosted evaluation surfaces, and private runtime (customer VPC / private cloud / on-prem) when production decisions must stay inside your trust boundary.
· Fail-closed: SDK and enforced paths that require a valid decision are designed to fail closed on timeout or invalid response. Skipping the call means the write is not under Protect.

Technical detail for engineers: Security & data handling (docs).

Controls we describe publicly

· HTTPS / TLS for public website and API surfaces
· Least-privilege connector and credential design where customers configure access
· Read-oriented evidence access for many Lab/demo connectors (scope is customer-controlled)
· Secrets and tokens kept out of Trace™ decision payloads by design
· Trace™ records decision outcomes, reasons, and evidence provenance metadata as configured
· Tenant / data separation on multi-tenant hosted paths as implemented for the product surface in use
· Logging and auditing of assurance decisions for the configured deployment

These are product design and operational practices. They are not a substitute for your own security review or an independent audit report.

Certification status

TekCapitol is not SOC 2 certified today. We do not claim ISO 27001, HIPAA, PCI, or penetration-test certification on this site.

Where pages mention frameworks (for example NIST AI RMF), we mean control mapping / evaluation support for your policies, not that TekCapitol itself is certified or compliant against those frameworks.

Responsible disclosure

If you believe you have found a security vulnerability in a TekCapitol public website or product surface, please report it in good faith.

How to report

Email info@tekcapitol.com with subject line Security vulnerability report.

(A dedicated security@tekcapitol.com mailbox is not configured as a public inbox at this time. Use the address above until one is published.)

Please include
· Affected URL or product surface
· Description of the issue and impact
· Steps to reproduce (non-destructive)
· Your contact information
Please do not
· Access or modify other customers’ data
· Disrupt availability with destructive testing
· Publish exploit details before we have had a reasonable chance to investigate and remediate

We aim to acknowledge reports within 5 business days. Complex issues may take longer to validate.

Related pages

Data & Confidentiality · Privacy · Terms · AI / Model Data Use