Security & Trust
What's in place today, how your data is handled in each deployment mode, and what's on the roadmap. We'd rather show you the timeline than misrepresent the posture.
In place today
- Apache-2.0 edge daemon — source available for review
- Bearer-token auth on inbound gRPC; mTLS for Enterprise
- Encrypted WireGuard mesh (Tailscale or self-hosted Headscale)
- Role-based access control — Owner / Admin / Member
- Database-enforced tenant isolation (PostgreSQL row-level security)
- Immutable audit log on every action — actor, timestamp, resource
Data handling by deployment mode
Galois Cloud
Multi-tenant on our infrastructure. Every tenant isolated by PostgreSQL row-level security. Bring your own storage bucket (R2 / S3 / MinIO / GCS).
Dedicated tenant
Single-tenant cloud with customer-controlled storage and a per-org mesh namespace. Regional pinning available.
On-prem / Airgapped
Daemon and platform run entirely on your hardware with your LLM endpoint. No prompts, responses, or measurement data leave your network.
Report a vulnerability
Email security@galoislabs.ai. We acknowledge reports within three business days and will keep you updated through remediation. Please give us a reasonable window to fix an issue before public disclosure.
On the roadmap
Compliance and hardening work in flight. See the full status table on the deployment page.
- Signed binaries (Azure Trusted Signing) — rolling out
- SBOM (CycloneDX) per release — Q3 2026
- FIPS 140-3 crypto mode — Q4 2026
- STIG hardening guide — Q4 2026
- FedRAMP Moderate — 2027