The keys stay yours. So does the audit trail.
QuasiHuman deploys inside your own AWS account, in your region, against your KMS keys — we run the fleet and never hold the credentials. Everything an agent does from there is bounded before it starts, gated where the consequences are real, and recorded with provenance you can replay step by step.
Your agents. Your account. We run the fleet. We never hold the keys.
Credential custody
Your system keys stay in your secrets manager. We never hold them.
Data residency
Conversations, memories and artifacts never leave your account or region.
Blast radius
One tenant is one AWS account — not one row with a tenant_id on it.
Cost transparency
The infrastructure bill is yours, itemised by your own cloud provider.
Two ways to run seats. Both of them end in the same audit trail.
Your directory is the source of truth.
Single sign-on against the identity provider you already run — Microsoft Entra and 365, Google Workspace, Zitadel, or your own OIDC. People sign in with the account they have, and their groups, team and role arrive with them.
- No second set of credentials to issue, rotate or breach
- Group membership maps straight onto what a person can reach
- Someone leaves the directory and their access ends with it
- Joiners and movers are handled by the process you already have
Or we hold the seats.
Add a person from the supervision console, set what they can reach, done. No integration work, no directory project, nothing to schedule with an identity team that is already busy.
- Invite, suspend and remove people from the dashboard
- Seats, roles and scopes set per person, visible in one place
- Sensible starting roles rather than a permissions essay
- Move to federation later without losing history or scopes
Whichever way the seats are run, the team, role and level a person signs in with are what the agent authorises against on every call — the same colleague, asked the same question by two different people, answers from what each of them is cleared to see.
Autonomy you can audit. Every action logged, replayable, reversible — and stoppable.
Every action an agent takes is logged with provenance and can be replayed step by step. Anything above a blast-radius threshold stops and waits for a named human — and a held run costs nothing while it waits.
Autonomy without auditability is recklessness. So here are the controls, in plain terms.
It runs inside your boundary
Deployment happens in your AWS account. Conversations, memories, artifacts and your internal-system credentials never leave it. There is no copy of your data on our side to breach.
Least-privilege by construction
An agent can only do what its granted tools allow. No ambient database access, no standing admin session, no credential it could use for something you didn't sanction.
Human gates on real consequences
Mutations above a blast-radius threshold stop and wait for a named human. The agent parks, keeps its state, and resumes on the decision — approve, amend or refuse.
Everything is on the record
Every action, input, tool result and decision is recorded with provenance and can be replayed step by step. 'Why did it do that' is a query, not an investigation.
Bounded by design
Token, cost, wall-clock and tool-iteration ceilings apply to every run, with circuit breakers on repeated failure and a kill switch that stops a workflow mid-flight.
Your systems are untrusted input
Anything a tool returns is isolated and marked before the model reads it — the standard defence against prompt injection arriving through your own data.
We don't display compliance badges we haven't earned. Ask us where we are on SOC 2 and we'll tell you the truth, with dates — and in the meantime, the architecture above is what your security team should actually be reviewing.
Bring the security team who will ask hard questions.
That is a feature, not an obstacle. This architecture was built to survive the review — and the review is the fastest way to find out whether we are telling the truth.