GateHouse
Security & trust

Sovereignty is architectural, not contractual.

Most platforms promise not to look at your data. GateHouse is built so the raw data is never sent — and proves what crosses the boundary. Here is how the guarantees hold.

Sealed
Your data
never leaves
Attested insightΣ
raw rows touched: 0·insights returned: 1sealed
How the guarantee holds

Four architectural facts.

Metadata-only control plane

GateHouse central servers receive metadata only. Raw data never reaches them — the sovereignty claim is a property of the architecture, not a clause in a contract.

Policy-gated boundary

Every disclosure — even metadata destined for GateHouse — must pass the owner’s policy gate first. One gate primitive, applied recursively at every boundary.

Provable governance

ABAC policy authored in Cedar runs in enforcement or attestation mode, so guarantees are formally checkable, not merely tested.

Zero rows exported

Analysis runs where the data lives. The inviolable counter on every surface reads zero rows exported, and it stays there.

Controls

The operational safeguards.

Encryption

In transit and at rest for all metadata GateHouse holds.

SSO, SCIM & RBAC

Enterprise identity, provisioning and role-based access on the console.

Time-boxed support access

Delegated support access is customer-granted, expiring, and fully logged.

Settlement-grade audit

Policy, egress, agent and admin events logged and exportable.

EU/UK residency by default

Data residency is a default posture, with SCCs where transfer is required.

Signed workloads

Buyer workloads are admitted with provenance, signature and resource limits.

Compliance

Where we stand.

We state posture as fact, and mark what is in progress honestly. Architecture does much of the work that certifications attest to.

GDPRAligned
EU/UK data residencyDefault
SOC 2 Type IIIn progress
ISO 27001In progress

Bring your security team.

We answer the hard questions about the boundary and the control plane directly.