Home/Trust & Security
Trust & Security

Security and governance built into the platform, not bolted on.

Zero-trust architecture, sub-millisecond policy enforcement, and sovereign deployment options — designed for regulated environments from day one.

Procurement-ready trust portal

trust.budecosystem.com — SOC 2 / ISO 27001 reports, subprocessor list, security policies, pen-test summaries. Self-serve, NDA-gated.

Open trust portal
Compliance posture

An honest table. Dated, not aspirational.

Reports available on request under NDA. As of Q2 2026.

FrameworkStatusNotes
SOC 2 Type IICertifiedAnnual audit · report on request
ISO 27001CertifiedInformation security management, full platform scope
EU AI ActReadyArticle-level mapping available below
HIPAACompliant by deploymentBAA available · sovereign mode
FedRAMPRoadmap · Q3 2026In progress with sponsoring agency
PCI-DSSAdjacent / by deploymentScoped per customer environment
Architecture principles

Four guarantees, native to every layer.

Zero-trust

Every call authenticated, every action authorized — no implicit trust between components.

RBAC + ABAC

Fine-grained policy at the agent and tool level, not just the API boundary.

Audit logging

Tamper-evident, exportable, with configurable retention.

Data residency

Your data never leaves your environment. No egress paths by default.

Bud SENTRY

Governance at 0.70ms.

Real-time guardrails enforced in-line with inference. PII detection, jailbreak resistance, and policy compliance — without a latency penalty. 8.39ms on CPU versus 18–19ms on a $15K GPU; roughly 239× cheaper per million guardrail calls.

Read SENTRY documentation
InboundPrompt + context
SENTRYGuardrails · PII · policy0.70ms
ModelInference
SENTRYOutput check · audit logtamper-evident
ReturnGoverned response
Sovereign deployment

Reference deployments across three jurisdictions.

India

National-scale government deployment — air-gapped, on-prem, 60K+ users.

UAE

In-country sovereign reference, data resident within national borders.

South Korea

Regulated-industry deployment under local data-protection regime.

Sovereign deployment guide
EU AI Act readiness

Mapped article by article.

High-risk system requirements enforce August 2026. The full mapping is in the whitepaper; a summary follows.

ArticleRequirementBud capability
Art. 9Risk management systemSENTRY policy engine + continuous evaluation gates
Art. 10Data governanceBud Model Foundry lineage + dataset versioning
Art. 12Record-keeping & loggingTamper-evident audit trail, exportable
Art. 14Human oversightBud Studio approval flows + override controls
Data flow guarantees

Where your data goes — and where it doesn't.

Your perimeter · zero egress
IngressTLS · your IdP
Authenticated requestEncrypted in transit · RBAC + ABAC enforced at the boundary
Runtime & data planes
Agent runtimeOrchestration · memory · tools
Data planeRAG · vector · knowledge — resident
Serving
Bud AI Foundry · inferenceModels run on your hardware · encrypted at rest
Silicon
Your CPUs / GPUs · on-prem to air-gappedZero external dependencies
Bud SENTRY · inline guardrails & audit
No outbound calls to external model APIs  ·  encryption in transit & at rest

Questions for our security team?

A direct line to the team that owns these answers — not a generic contact form.

Get started with Bud

Put your data on it.

The fastest way to see what an integrated AI operating system does for your enterprise is a proof-of-concept on your infrastructure, with your data.

01 Identify a use case where complexity, cost, or governance is a known pain point.
02 Joint discovery — Bud maps your AI pain points to platform capabilities.
03 POC in days, on your hardware, with your data.