Xybern decides whether every agent action runs, so we secure the layer itself, at every hop, with encryption, isolation, and a signed record you can verify. Your operations are nobody else’s business.
Because Xybern is inline, not alongside, we answer the question every architect asks first: what if Xybern itself fails? Explicitly, by design.
If the judge or the engine is unavailable, actions escalate or are blocked in the gateways and relay; the SDK fails closed in enforce mode. Fail-open is an explicit opt-in, never a default.
Every record is workspace-scoped; cross-workspace access returns a hard 403. Dedicated and Sovereign deployments give you your own database and keys.
Deterministic rules see action type, identity and metadata. Content is evaluated only by the mandates you write, and can stay inside your network with the relay or a dedicated deployment.
Isolation is the default state at storage, compute, network, and queue, from the moment a workspace is provisioned.
We share our control matrix, Deployment Manifest, benchmark results and test reports with your security and procurement teams directly. Certifications are stated as they are: ISO/IEC 27001 is our first target, SOC 2 follows. We do not claim to be SAMA certified.
Every control mapped to SAMA CSF, NCA ECC, PDPL and ISO 27001 clauses, with evidence pointers and honest status.
Request reportData processing agreement and Saudi data residency addendum available. Residency by deployment: Xybern Cloud (US), Saudi Private (Riyadh), Sovereign (your boundary).
Request DPAExternal application and AI agent red-team testing is scoped and scheduled; the XAAB benchmark is run continuously against the live layer.
Request summaryEvery verification is SHA-256 hashed, HMAC-signed, and chain-linked. Tamper-evident by construction, not by policy.
Every agent action travels over TLS, rests on encrypted volumes, and is sealed into a signed vault entry.
Every ingress and egress path uses TLS 1.2 or later with modern cipher suites; dedicated deployments use your own certificates.
Provider volume encryption (AES-256 class) for databases and backups; vault secrets rotate without invalidating existing entries.
Connector and MFA secrets are encrypted at the application layer; signing keys live on your volume, in your KMS, or your HSM export.
Bring your own keys via your KMS or HSM. Provision, rotate, revoke, and attest, with every key event recorded in the vault.
Workspace isolation is the default. Move to a dedicated in-Kingdom environment, or run the whole layer inside your own infrastructure.
Xybern Cloud (shared, workspace-isolated), Dedicated and Saudi Private (single tenant, operated by Xybern), Sovereign (operated by you).
Evaluate policies locally and forward only what you must, keeping enforcement close to your systems.
Full on-premise or air-gapped deployment with no external dependency.
Saudi Arabia with Saudi Private, your own boundary with Sovereign, US on Xybern Cloud. Residency rules are also enforceable as mandates.
Strong authentication for people, cryptographic identity for agents, and roles that decide who may approve what.
TOTP authenticator apps with backup codes, enforced for owners and admins on dedicated and sovereign installs.
SAML and OIDC single sign-on (Entra ID, Okta and others) available on request for dedicated and sovereign deployments.
No self-service signup: workspaces are provisioned by Xybern and members are invited by your admins.
Role-based access with scoped, time-bound permissions for both people and agents.
Dedicated and sovereign deployments sit behind your VPN or private endpoints; access is restricted at the network edge.
Emergency access requires a named human and a recorded justification, sealed to the vault.
Each authorisation is written once to a hash-chained vault and can be verified on your own, without trusting us.
Every decision produces a signed, offline-verifiable receipt of what was allowed, escalated, or blocked.
Records are chain-linked and append-only. Any later change breaks the chain, which is how tampering is detected.
Verify any record with the public key. No call back to Xybern is required.
Export a scoped, signed pack for any period, agent, or single decision.
Sample audit logWe share architecture documentation, the control matrix, the Deployment Manifest and test reports directly with security and procurement. No NDA for the initial architecture review.