Security
How your data is handled.
Guardrail Ledger is part of Spot Suite, operated by Spot Cloud B.V. Scanners run on your agents. We store SARIF, SBOM, and exception records.
-
Microsoft Entra SSO
Sign-in runs through Spot Suite OIDC with Microsoft Entra. Guardrail Ledger does not keep a separate username database.
-
Dedicated Customer Environment
Every customer gets a dedicated Customer Environment with its own Cloudflare Worker. A paid buyer (invoice, card order without trial days, or Marketplace purchase) also gets its own Postgres database on Supabase in the region chosen at purchase. A trial, or a card order that starts with trial days, gets its own schema in the shared EU project (Paris); nothing moves it to its own database on first payment yet. Microsoft Azure is a subprocessor for purchases made through Azure Marketplace; see the subprocessor list.
-
Tenant-scoped access
SARIF, SBOM, exceptions, and gate decisions stay in your own tenant store. Cross-tenant access is not part of the product.
-
Seven regions, EU by default
The Postgres database of an order without trial days runs in the region chosen at purchase: EU (Frankfurt), UK (London), US (N. Virginia), Canada (Montréal), Asia–Pacific (Singapore) or Latin America (São Paulo). Middle East & Africa is hosted in the EU. The default is the EU. Trials, and card orders that start with trial days, run in the EU (Paris) whatever the region.
-
Audit log
Exception approvals, gate policy changes, SARIF uploads, and pipeline token changes are logged with who made them and when.
-
Source stays with you
Trivy, Gitleaks, Checkov, and Opengrep run on your Azure Pipelines agents. We do not clone the repo.
Security posture.
- Legal entity Spot Cloud B.V.
- Regulations we help with GDPR, DORA, and NIS2
- Authentication Microsoft Entra via Spot Suite OIDC
- Isolation model Own Worker for every customer; own Postgres database for orders without trial days; own schema in the shared EU project for trials
- Source code Stays on your agents
- What we store SARIF, SBOM, gates, exceptions
See the architecture in a demo.
Walk through agent-side scans, SARIF ingest, and the exception ledger using demo data.