Built for the questions your security team will ask.

The controls behind the platform, stated plainly — because “trust us” is not an architecture. Residency with an address, identity you already run, guardrails before the model, and a record of everything that happened.

3regional stacks
32guardrail detectors
26permissioned resources
AES-256GCM encryption
Data residency

Your data has an address.

Gecko runs independent production stacks in three AWS regions — not one global deployment with a residency setting. Each region has its own database, secrets, domain and worker fleet.

  • Ireland, the United States and Canada — a real answer for UK and EU, US and Canadian institutions
  • Jurisdiction-aware crawling — website crawls can egress through a UK proxy so content is fetched from the right place
  • Tenant isolation enforced on every query in the data-access layer, with a separate reader and writer
  • AWS hosted with SOC 2 and ISO 27001 assurance
Identity & access

Least privilege, down to a single agent.

Your identity provider signs people in. Roles decide what they can read, change or run. API tokens can never do more than the person who made them.

Single sign-on

SSO — including SAML — through Gecko’s identity service. In production the console is SSO-only: there is no separate password to phish.

SAMLSSO-only console

Roles that fit how you work

26 permissioned resource types with separate read, write and run — so someone can operate an agent they cannot edit. Custom roles can be scoped to specific agents, websites or workflows.

AdminBuilderOperatorViewer+ custom

API tokens done properly

Stored only as SHA-256 hashes and shown once. Tokens expire, can be revoked, record when they were last used, and can carry stricter guardrails than the tenant default.

Read onlyChatbotFull access
Built-in roles — plus unlimited custom roles per tenant
RoleReadWriteRun
Admin✓✓✓
Builder✓✓ except admin areas✓
Operator✓—✓
Viewer✓——
Guardrails

Screen input before the model ever sees it.

32 built-in detectors, informed by OWASP guidance for LLM applications, screen every message to agents, web widgets and API tokens before the model sees it — each rule can flag, redact or block. Phone-call transcripts are screened too, with matches flagging the call for review.

22

Prompt-injection detectors

From blunt instruction overrides to the attacks most filters miss: invisible Unicode, variation-selector smuggling and instructions hidden in retrieved content.

Ignore previous instructionsDisregard instructionsForget instructionsNew instructions markerDo not follow system instructionsActivate privileged modeSystem overrideReveal system promptRepeat instructionsRemove restrictionsJailbreak modeBypass safetyRole tag injectionRole delimiter spoofingControl token injectionChat-template delimitersInvisible Unicode controlsVariation-selector smugglingEncoded instruction directiveIndirect AI instructionMemory poisoningData exfiltration directive
10

Sensitive-information detectors

Personal data and credentials that should never reach a model — redacted with a placeholder you choose, or blocked outright. Credential detectors redact by default; personal-data detectors are switched on per guardrail group.

Email addressPhone numberSocial Security numberCredit card numberIP addressPrivate keyJSON Web TokenAWS access key IDCredential assignmentCredential-bearing database URI

Sensible defaults

Every new tenant starts protected: high-risk injection rules block and credential detectors redact from day one.

Your own rules

Add custom patterns, validated against catastrophic backtracking before they save, and try them in the in-console test bench.

Review what triggered

Hits appear in the run trace, auto-flag the conversation for human review and can be filtered in observability.

Audit & tracing

Who changed what. What ran, and why.

Two complementary records. The audit log captures configuration changes across the tenant. Run traces capture everything an agent or workflow actually did.

  • Audit log — every create, update and delete across 22 resource types, including roles, secrets, guardrails, API tokens, integrations and phone lines
  • Actor attribution — whether a person or an API key made the change, filterable by date, resource type and actor
  • Step-level run traces — inputs, model calls, token usage, every tool call, guardrail hits and approval outcomes
How observability works
Encryption, network & data

Controls that fail closed.

Secrets you can’t read back, outbound traffic that can’t reach your internal network, and code that never runs on the platform itself.

Encrypted, write-only secrets

Integration credentials and the tenant secrets vault use AES-256-GCM with a random IV per value and key-rotation support. Decryption fails closed, and values are never returned after save — not even to admins.

Guarded outbound traffic

Every outbound request — webhooks, MCP calls, model endpoints, crawls — is checked against private and reserved address ranges, including cloud metadata. Workflow webhooks leave through a mandatory egress proxy in production.

Isolated code execution

Custom Code runs in an isolated sandbox per execution with a hard time limit. Secrets arrive only as environment variables at run time, and leaked values are redacted from errors.

Hardened edges

Strict security headers on every response, allow-listed CORS, generic error bodies with request IDs, signature-verified Twilio webhooks and unguessable workflow webhook URLs.

Your data isn’t training data

Gecko does not train AI models on institutional data. Bring your own provider keys and inference runs under the agreement your institution already holds with that provider.

Operations without PII

Error tracking is configured not to send personal data. Gecko support access to a tenant is scoped and gated behind a platform-admin check.

Human oversight

Humans decide where it matters.

Policy becomes a step in the process: sensitive actions wait for a person, identities are verified before data is touched, and anything unusual lands in a review queue.

  • Approval gates as interactive cards in Slack or Teams, backed by single-use action tokens stored only as hashes
  • Identity verification with an emailed six-digit code — expiring, five attempts, verified email stamped on the conversation
  • Conversation review queue — guardrail hits auto-flag; reviewers record who flagged and who reviewed
Human-in-the-loop workflows
Accessibility & languages

Compliance enforced in code, not requested in guidelines.

Public bodies carry legal accessibility duties. The platform won’t let anyone publish a web experience that fails them.

WCAG 2.2 AA, enforced

Web embeds target 7:1 body-text contrast, and the API rejects themes that fail contrast checks. Keyboard-complete, screen-reader announcements, 400% zoom, reduced motion and forced colours.

Multilingual by design

The console is fully translatable, so teams can work in the languages they need — with each person’s choice remembered on every device. Light and dark themes too.

VPAT for your review

A VPAT supports accessibility review, and a dyslexia-friendly font option is available for student-facing web experiences.

Security FAQ

What your security team will ask.

Need more detail? Our Trust Center has our policies, controls and assurance documents.

Visit the Gecko Trust Center
Where does our data live?

In one of three independent regional deployments — Ireland (eu-west-1), the United States (us-east-1) or Canada (ca-central-1). Each has its own database, secrets, domain and worker fleet. Tenant isolation is enforced in the data-access layer on every query.

Is our data used to train AI models?

No. Gecko does not train AI models on institutional data. When you bring your own provider keys, model inference runs under the data-processing agreement your institution already holds with that provider — for example an Azure agreement through Microsoft Foundry.

Do you support single sign-on?

Yes. Single sign-on, including SAML, is provided through Gecko’s identity service, and the console is SSO-only in production.

Can we limit who builds, edits and runs agents?

Yes. Role-based access control covers 26 resource types with separate read, write and run permissions. Use the built-in Admin, Builder, Operator and Viewer roles, or create custom roles — including roles scoped to specific agents, websites or workflows.

Can we see who changed what?

Yes. The audit log automatically records every create, update and delete across 22 resource types — including roles, secrets, guardrails, API tokens and phone lines — with the acting user or API key. Every agent and workflow run also keeps a complete step-level trace.

How do you defend against prompt injection?

32 built-in detectors screen input before any model call, including 22 prompt-injection rules covering instruction overrides, delimiter spoofing, invisible-Unicode smuggling and encoded instructions. Rules can flag, redact or block, and you can add your own patterns. Guardrails work alongside approval gates and full tracing as layered defence.

How are credentials and secrets protected?

They are encrypted with AES-256-GCM, support key rotation and are write-only — never returned by the API or console after save. API tokens are stored only as SHA-256 hashes, expire, and can never exceed their creator’s permissions.

What certifications do you hold?

The platform is hosted on AWS with SOC 2 and ISO 27001 assurance, and a VPAT supports accessibility review. Policies, controls and assurance documents are available in our Trust Center

The deeper read

The AI Governance Briefing for IT leaders.

The problem, the direction of travel, and seven questions to ask any AI vendor — including us. No form, no gate.

  • Ungated PDF download
  • Assurance documents in our Trust Center
  • Architecture walkthrough with your team
Download the briefing