Topic

Agent Security and Governance

Running agents without giving away more than you meant to. These pages cover scoped credentials and key rotation, permission boundaries, prompt injection and tool poisoning, sandboxing, data retention, audit trails, and the review process around autonomous output. Fast.io supports this with scoped API keys, granular workspace permissions, encryption in transit and at rest, and an append-only audit log. It is not SOC 2, ISO 27001, or HIPAA certified, and it runs on certified infrastructure partners rather than claiming those certifications itself.

Coverage assumes an agent with real access rather than a demo, so the pages spend their time on blast radius: what a confused or compromised agent could reach, how to shrink that before it matters, and what evidence you would have afterwards. They describe specific controls rather than certifications, and they say which ones are worth putting in place first when you cannot do everything at once.

34 guides in this topic.

Start here

All guides

Related topics

All topics / Resource library