> Source: https://planckproof.ai/security  |  Plain-Markdown twin of the page.

Security & Safety

# Autonomous, and under your control

Running an attacker against your live systems is only acceptable if the controls are real and enforced in software. Here is exactly how scope, safety, and your data are handled.

[Get a Quote](https://planckproof.ai/quote)

[Trust & Data Handling](https://planckproof.ai/trust)

Safe In Production

## Four controls, enforced in the system

Not promises in a slide. Each of these is a property of how the agent runs, not a policy we ask you to trust.

Boundary

### Scope is a wall

Testing stays inside the assets and windows you define, enforced in software rather than left to judgment in the moment. Discovery never becomes a reason to reach further.

Restraint

### Non-destructive by default

The agent runs read-mostly, honors rate limits, and paces its traffic. Anything with real side effects is blocked unless you authorize it in writing.

Control

### Approval gate and kill switch

Sensitive actions wait for your explicit approval, and you can stop any run instantly. You are never watching a black box you cannot halt.

Accountability

### Human validation on demand

Route any finding, or an entire run, through a senior practitioner before it reaches your tracker, when you want a person accountable for the result.

Your Data

## Held only as long as the work requires

The agent runs from infrastructure we scope with you, and it can be routed through your own egress where a fixed source address is required. What it learns about your systems is treated as engagement data, not training material.

The full commitments, including retention and destruction, live on our [Trust and Data Handling](https://planckproof.ai/trust) page.

- **Encrypted in transit and at rest.** Engagement data is protected end to end while we hold it.
- **Least access.** Only the assigned team can reach your data, for the duration of the work.
- **Destruction on your schedule.** Report material is removed on the timeline you set.
- **Routed through your egress.** Where you need a fixed, allowlisted source address, the agent uses it.

Frameworks

## Mapped to the standards your auditors expect

Traditional offensive-security method, plus the emerging frameworks for testing AI systems.

OWASP WSTG

OWASP API SECURITY TOP 10

OWASP LLM TOP 10

PTES

NIST SP 800-115

CVSS V3.1

MITRE ATT&CK

MITRE ATLAS

NIST AI RMF

ISO 42001

[Responsible Disclosure](https://planckproof.ai/responsible-disclosure)

Get Started

## Bring it to your security team

We are happy to walk your security and compliance stakeholders through the controls before anything runs against your systems.

[Get a Quote](https://planckproof.ai/quote)

[Read Our Methodology](https://planckproof.ai/methodology)
