# Security | Sealgate AI Agent Data Security

How Sealgate secures agentic AI: zero-knowledge encryption at rest (AES-256-GCM, HKDF-SHA256), deterministic CEL policy enforcement, lethal-trifecta protection, per-user isolation, full audit trails with 120-day retention, and supply-chain pinning. Deploy as SaaS, VPC, self-hosted, or air-gapped.

Source: https://sealgate.ai/security

---

// Safety net only. Both entry points preload the chunk they are about to // render, so in practice nothing here suspends. It exists so a route // added without a matching SPLIT_ROUTES entry degrades to a blank frame // instead of throwing.

[Docs](https://sealgate.ai/docs/) [Product](https://sealgate.ai/product)

AI Data Leaks

[Blog](https://sealgate.ai/blog/) [Pricing](https://sealgate.ai/pricing) [Try for Free](https://dashboard.sealgate.ai) Get Demo

Security

# Security you can verify

Auth, RBAC, and data security for agentic AI. Deterministic controls, not probabilistic guardrails. Every claim links to the docs, so you can check it yourself.

## Zero-knowledge encryption at rest

Your key never reaches our servers.

- AES-256, encrypted at rest
- Key derived from a secret only you hold
- We store a hash, never the key
- A DB breach leaks only unreadable ciphertext [Read the security model ↗](https://sealgate.ai/docs/security/self-serve-security/)

GITHUB_TOKEN SLACK_TOKEN AWS_SECRET_KEY $SEALGATE$1$a3B... $SEALGATE$1$k7P... $SEALGATE$1$mN2... Personal Encryption Key Sealgate Databases $SEALGATE$1$a3B... $SEALGATE$1$k7P... $SEALGATE$1$mN2... Your Device Sealgate cannot read encrypted credentials

## Lethal-trifecta protection

Three risks at once, and we pause it.

- Private data access
- Untrusted content in the session
- A channel to send data out
- All three present: a human approves before anything leaves [The lethal trifecta ↗](https://sealgate.ai/docs/ai-security-threats/lethal-trifecta/)

The AI leaked sensitive data ! Sealgate blocked the leak Your AI Agent Attacker Malicious Email with jailbreak instructions Malicious Email with jailbreak instructions

## Full audit trail, streamed to your SIEM

Every tool call logged, streamed to your SIEM.

- Splunk or any SIEM endpoint
- Metadata and parameters logged
- Raw files and conversations never stored
- 120-day retention, configurable 1 to 365 [SIEM integration ↗](https://sealgate.ai/docs/enterprise/siem-integration/)

Your Infrastructure (VPC / On-Prem) Sealgate Gateway MCP MCP MCP SIEM CEF:0|tool_call|read_file|5|ok CEF:0|security|trifecta_flag|8|block CEF:0|tool_call|send_msg|5|ok CEF:0|admin|config_change|3

## Compromised connectors, severed on report

A poisoned connector gets cut, fast.

- Every connector runs through the gateway
- A reported compromise severs that route
- Every other connector keeps working [Dependency pinning ↗](https://sealgate.ai/docs/security/mcp-dependency-pinning/)

AI agent Sealgate Gateway MCP servers Attacker An attacker compromises one MCP server Blocked the moment the compromise is reported

Also built in

### Deterministic policy enforcement

Rules in a CEL engine, not a probabilistic guardrail.

- Every tool tagged PUBLIC, PRIVATE, or SECRET
- One-way lattice: SECRET never flows down to PUBLIC [How enforcement works ↗](https://sealgate.ai/docs/ai-security-threats/)

### Per-user isolation

One isolated gateway per user.

- Its own connector processes
- No shared state between users

## Deploy where your policy requires

SaaS VPC Self-hosted Air-gapped

SaaS, your own VPC, self-hosted, or fully air-gapped. Self-hosted means Sealgate never processes or accesses your data.

## Want the deep dive with your security team?

Book a walkthrough of the threat model, controls, and deployment options, or read the full security documentation.

[Book a demo](https://cal.com/eito80/demo) [Read the security docs](https://sealgate.ai/docs/security/)

### Contact Us

Sealgate (GPU-EVM LTD)

3rd Floor, 86-90 Paul Street

London EC2A 4NE

Email: hello@sealgate.ai

### Legal

[Terms of Service](https://sealgate.ai/terms-of-service) [Privacy Policy](https://sealgate.ai/privacy-policy) [Subprocessors](https://sealgate.ai/subprocessors) [Data Processing Addendum](https://sealgate.ai/dpa)

### Quick Links

[Home](https://sealgate.ai/) [Product](https://sealgate.ai/product) [Pricing](https://sealgate.ai/pricing) [Security](https://sealgate.ai/security) [About](https://sealgate.ai/about) [Contact](https://sealgate.ai/contact) [Brand](https://sealgate.ai/brand) [Press](https://sealgate.ai/press) [Docs](https://sealgate.ai/docs/) [Blog](https://sealgate.ai/blog/)

### Connect

[Connect AI to messaging](https://sealgate.ai/connect) [WhatsApp](https://sealgate.ai/connect/whatsapp) [iMessage](https://sealgate.ai/connect/imessage) [Telegram](https://sealgate.ai/connect/telegram) [LinkedIn DMs](https://sealgate.ai/connect/linkedin) [Signal](https://sealgate.ai/connect/signal) [Instagram DMs](https://sealgate.ai/connect/instagram) [Messenger](https://sealgate.ai/connect/messenger) [X DMs](https://sealgate.ai/connect/x) [Discord DMs](https://sealgate.ai/connect/discord) [LINE](https://sealgate.ai/connect/line) [Beeper](https://sealgate.ai/beeper)

### Follow Us
