Deployment Model
The entire platform, including the orchestrator, data-source agents, WebSocket server, UI, reporting engine, and audit storage, runs on the customer’s infrastructure. There is no cloud-hosted instance.Agent Security Model
Each connected data source has a dedicated agent, a containerized service that holds credentials only for its assigned source. The Main Agent (orchestrator) never holds database credentials and never directly accesses customer databases. Each agent runs in its own Docker container with isolated filesystem and memory. A compromised agent cannot access another agent’s data or credentials.Agent Security Model
Full details on agent isolation, credential separation, and security boundaries
What the LLM Receives
The LLM is a stateless inference service. Each request is constructed from scratch with no memory between calls.
Customer data, queries, and knowledge nodes are never used to train or fine-tune models. The LLM provider receives stateless inference requests only.
Authentication
SSO Integration
Superatom delegates authentication to the customer’s existing identity infrastructure:Session Management
- JWT tokens with configurable expiration
- Automatic logout on inactivity
- All authentication over HTTPS
- Disabling a user in the IdP immediately revokes Superatom access
Authorization
Role-Based Access Control
Data-Level Permissions
Permissions are enforced at the query planning stage, before any SQL is generated or data is accessed. Rephrasing a question does not bypass permissions.
Encryption
Audit Logging
Every interaction is recorded in an immutable audit trail stored on the customer’s infrastructure:
The audit trail is immutable, queryable within Superatom, and exportable to SIEM systems.
Tenant Isolation
For multi-department or multi-business-unit deployments:SQL Injection Prevention
All queries use parameterized statements:Prompt Injection Defense
1
Input Sanitization
User inputs cleaned before processing
2
Prompt Structure
System prompts separated from user input
3
Output Validation
AI outputs validated before execution
4
Action Confirmation
Write operations require human approval through configurable approval gates
Company Access
Superatom as a company does not have access to customer deployments. There is no remote access, admin portal, or backdoor. Support is provided using only usage telemetry: query counts, response times, error rates, and feature usage.Further Reading
Agent Security Model
Agent isolation and credential separation
Data Protection
Zero-storage architecture and encryption
Access Control
Permission system and enforcement
Action Safety
Approval gates and write-back controls
Network & Data Flow
What leaves your network and air-gapped options
Compliance
SOC 2, GDPR, HIPAA, ISO 27001