Skip to content
Gatewise

Security and trust

Product principles we design against

Gatewise sits in a sensitive position: in front of actions that move money, change records and reach customers. These are the principles that position demands.

  • Least privilege

    Gatewise requests the narrowest access it needs to read the evidence a policy depends on. Read access for evidence is separate from any execution path.

  • Deterministic policy enforcement

    Decisions are produced by code and data, not by a model. The same action with the same evidence returns the same decision every time.

  • Evidence-based decisions

    A decision cites the records it used. If a required record is missing or stale, the result is INSUFFICIENT EVIDENCE rather than an assumption.

  • Audit trail

    Every proposed action is recorded with the agent, policy, evidence, decision, reason, approval and execution status.

  • Fail-safe behaviour

    When Gatewise cannot evaluate an action, the safe outcome applies. High-impact action types do not fall through to execution on error.

  • Customer-controlled policies

    You own your policies, thresholds, approver roles and enforcement scope. Gatewise does not set business rules on your behalf.

Scope

What we do not claim

Clear limits are part of trust.

  • We do not list certifications we do not hold.
  • We do not claim live integrations with named vendors. Evidence sources are described by category.
  • We do not present interface examples or metrics on this site as customer results.
  • We do not replace your security review. We give your policies an enforcement point.

Give your agents freedom without giving them a blank cheque.

Tell us what your agents are allowed to do today. We will review whether Gatewise fits your agent workflow.

Works with your agents and existing business tools