Skip to content

Security

Adversarial by origin. Isolation by law. No fake seals.

Last updated 2026-09-05. Report: security@tuce.ai. No public status page yet — Trust Center says operational.

TUCE sits above the developer’s graphs and below the enterprise security boundary. Framework-agnostic. Models advise. Deterministic gates decide.

The governance substrate enterprise security teams need to approve agent deployments — fail-closed invoke, origin isolation, dual-authority, and a private examiner. Not another graph library.

Privileged acts require dual authority: the human or session principal and the agent identity must independently authorize. Missing either fails closed. The intersection of permissions is what actually fires.

The adversarial layer was original and was upgraded: robustness, red-team and debate, critic, sandbox isolation. TUCE-owned names only.

Privileged acts run health, policy, injection, schema, and cost before they fire. Liveness is not readiness. Critical injection always blocks. Cognition menus are the operator UI over that plane — not a narrative layer over a missing runtime.

Transport is TLS on deployed origins. Console boards (HSM, ZTNA, WebAuthn, STRIDE, ISO 27001, SOC 2) are operator tools — they are not a Type II letter. STRIDE and SoA engines are aligning work, not certificates.

PEPs sit at input / plan / tool / output. Critical prompt injection always blocks. Encrypted memory and secrets fail-closed when a key is missing — they are never invented. Enterprise identity (SSO + directory sync + group→role + revoke on deprovision) is an aligning path. VEMO already publishes “No SAML on this door.” TUCE does not imply family-wide SSO.

We do not display SOC 2 or HIPAA badges on this origin. “Enterprise-grade” here means fail-closed gates and origin isolation, not a certificate number we do not have. Evidence packs, dual-control, and signed audit intent live on Trust. Aligning, not certified.

MLSecOps — engines, not letters

Map the public wheel onto TUCE-owned names. Do not import vendor lists as if they were us. Adapter supply-chain is named. Applicability Map stays aligning.

WheelTUCE nameStatus
Threat detectionThreat Weaveengine, not a SOC
Model hardeningAdversary GymHAVE · battery analogue
Dataset integrityClaim Filter + examinerANALOGUE
DriftDrift Scope / MidthoughtHAVE
Secure deployPEPs + Isolation Score + fail-closed invokecanary analogue
Adapter supply chainAdapter Supply CheckHAVE as of 8.4.7
ExplainabilityTruth Gate lensesHAVE
AuditDigital threadHAVE
Compliance letterApplicability Mapaligning, not certified
Workplace IAM / backupMSP desksPARTNER

MSP trust content stays on msp.tuce.app. Health desks require a BAA before PHI.

Hub: Trust Center · Subprocessors · Accessibility

Doors that actually exist

  • Google / X sign-in

    This console’s Better Auth door. SAML / directory sync is aligning, not claimed live on every family origin.

  • Stripe

    Lives on product origins, not this marketing origin.

  • GoHighLevel

    VEMO factory runtime — on the VEMO origin.