Akili

In progress, honestly.

Security & Trust

Here's exactly how it works — not a badge, the actual architecture. Formal third-party certifications are in progress; here's what's already true today.

Audit trail

Every mutating action is logged automatically, org-scoped, and reviewable — no per-endpoint instrumentation required to catch a change.

Encryption for credentials

API keys, provider credentials, and MCP server secrets are encrypted at rest at the database layer, not stored in plaintext anywhere in the platform.

Role-based access control

Permissions are enforced down to individual actions on the server — read and write are separately grantable on every resource, not a UI-only convenience.

SSO, SAML & OIDC

Bring your identity provider. Org membership provisioning is opt-in per organization by design, not an automatic join on first login.

SSO and SCIM deprovisioning

When someone leaves, SCIM removes their access automatically. Auto-provisioning new users via SCIM is on our roadmap — today, invites are explicit.

SCIM handles deprovisioning today; auto-provisioning is in progress.

Self-hosted, if you need it

Run the full platform — chat, agents, knowledge, memory, integrations — inside your own infrastructure. The public marketplace and org billing plane are cloud-only.

Certifications: in progress

We don't have a SOC 2 or ISO badge to show you yet. Rather than a badge-shaped graphic for something we haven't completed, here's the real architecture above — reviewable today, no wait required.