Single sign-on
SSO — including SAML — through Gecko’s identity service. In production the console is SSO-only: there is no separate password to phish.
The controls behind the platform, stated plainly — because “trust us” is not an architecture. Residency with an address, identity you already run, guardrails before the model, and a record of everything that happened.
Gecko runs independent production stacks in three AWS regions — not one global deployment with a residency setting. Each region has its own database, secrets, domain and worker fleet.
Your identity provider signs people in. Roles decide what they can read, change or run. API tokens can never do more than the person who made them.
SSO — including SAML — through Gecko’s identity service. In production the console is SSO-only: there is no separate password to phish.
26 permissioned resource types with separate read, write and run — so someone can operate an agent they cannot edit. Custom roles can be scoped to specific agents, websites or workflows.
Stored only as SHA-256 hashes and shown once. Tokens expire, can be revoked, record when they were last used, and can carry stricter guardrails than the tenant default.
| Role | Read | Write | Run |
|---|---|---|---|
| Admin | ✓ | ✓ | ✓ |
| Builder | ✓ | ✓ except admin areas | ✓ |
| Operator | ✓ | — | ✓ |
| Viewer | ✓ | — | — |
32 built-in detectors, informed by OWASP guidance for LLM applications, screen every message to agents, web widgets and API tokens before the model sees it — each rule can flag, redact or block. Phone-call transcripts are screened too, with matches flagging the call for review.
From blunt instruction overrides to the attacks most filters miss: invisible Unicode, variation-selector smuggling and instructions hidden in retrieved content.
Personal data and credentials that should never reach a model — redacted with a placeholder you choose, or blocked outright. Credential detectors redact by default; personal-data detectors are switched on per guardrail group.
Every new tenant starts protected: high-risk injection rules block and credential detectors redact from day one.
Add custom patterns, validated against catastrophic backtracking before they save, and try them in the in-console test bench.
Hits appear in the run trace, auto-flag the conversation for human review and can be filtered in observability.
Two complementary records. The audit log captures configuration changes across the tenant. Run traces capture everything an agent or workflow actually did.
Secrets you can’t read back, outbound traffic that can’t reach your internal network, and code that never runs on the platform itself.
Integration credentials and the tenant secrets vault use AES-256-GCM with a random IV per value and key-rotation support. Decryption fails closed, and values are never returned after save — not even to admins.
Every outbound request — webhooks, MCP calls, model endpoints, crawls — is checked against private and reserved address ranges, including cloud metadata. Workflow webhooks leave through a mandatory egress proxy in production.
Custom Code runs in an isolated sandbox per execution with a hard time limit. Secrets arrive only as environment variables at run time, and leaked values are redacted from errors.
Strict security headers on every response, allow-listed CORS, generic error bodies with request IDs, signature-verified Twilio webhooks and unguessable workflow webhook URLs.
Gecko does not train AI models on institutional data. Bring your own provider keys and inference runs under the agreement your institution already holds with that provider.
Error tracking is configured not to send personal data. Gecko support access to a tenant is scoped and gated behind a platform-admin check.
Policy becomes a step in the process: sensitive actions wait for a person, identities are verified before data is touched, and anything unusual lands in a review queue.
Public bodies carry legal accessibility duties. The platform won’t let anyone publish a web experience that fails them.
Web embeds target 7:1 body-text contrast, and the API rejects themes that fail contrast checks. Keyboard-complete, screen-reader announcements, 400% zoom, reduced motion and forced colours.
The console is fully translatable, so teams can work in the languages they need — with each person’s choice remembered on every device. Light and dark themes too.
A VPAT supports accessibility review, and a dyslexia-friendly font option is available for student-facing web experiences.
Need more detail? Our Trust Center has our policies, controls and assurance documents.
Visit the Gecko Trust CenterIn one of three independent regional deployments — Ireland (eu-west-1), the United States (us-east-1) or Canada (ca-central-1). Each has its own database, secrets, domain and worker fleet. Tenant isolation is enforced in the data-access layer on every query.
No. Gecko does not train AI models on institutional data. When you bring your own provider keys, model inference runs under the data-processing agreement your institution already holds with that provider — for example an Azure agreement through Microsoft Foundry.
Yes. Single sign-on, including SAML, is provided through Gecko’s identity service, and the console is SSO-only in production.
Yes. Role-based access control covers 26 resource types with separate read, write and run permissions. Use the built-in Admin, Builder, Operator and Viewer roles, or create custom roles — including roles scoped to specific agents, websites or workflows.
Yes. The audit log automatically records every create, update and delete across 22 resource types — including roles, secrets, guardrails, API tokens and phone lines — with the acting user or API key. Every agent and workflow run also keeps a complete step-level trace.
32 built-in detectors screen input before any model call, including 22 prompt-injection rules covering instruction overrides, delimiter spoofing, invisible-Unicode smuggling and encoded instructions. Rules can flag, redact or block, and you can add your own patterns. Guardrails work alongside approval gates and full tracing as layered defence.
They are encrypted with AES-256-GCM, support key rotation and are write-only — never returned by the API or console after save. API tokens are stored only as SHA-256 hashes, expire, and can never exceed their creator’s permissions.
The platform is hosted on AWS with SOC 2 and ISO 27001 assurance, and a VPAT supports accessibility review. Policies, controls and assurance documents are available in our Trust Center
The problem, the direction of travel, and seven questions to ask any AI vendor — including us. No form, no gate.