SECURITY & TRUST

Clear boundaries. Concrete security questions.

Understand the data Milgram handles, the controls around access, and the responsibilities to establish before a production rollout.

KNOW WHAT THE BOUNDARY HOLDS

Security evidence
deserves security controls.

Milgram handles AI traffic and session records that may contain sensitive information. Treat that data as part of your security architecture.

The proxy inspects original client content. Policy masking and compression can transform what is forwarded to a model provider, while inspection and audit paths can retain the original input. Masking is therefore not a claim of zero storage or zero visibility inside Milgram.

During evaluation, map the complete data path: client, proxy, worker, persistence, provider, dashboard, and any external AI used for investigation. Establish who can access the evidence and what processing is allowed at each point.

Customer-managed deployment places operating responsibilities in your environment. A hosted evaluation needs its own agreed data-handling and service boundaries.

IMPLEMENTED CONTROLS

Access should match responsibility.

Scoped administration

User capabilities and authorized scopes constrain the actions exposed through the API and MCP. Separate investigation access from permissions to change rules or policies.

Account protection

The authentication implementation includes TOTP multi-factor enrollment and recovery-code flows. Confirm the enrollment and administrative practices appropriate to your deployment.

Revocable AI connections

Connected MCP clients receive scoped authorization. Review their granted access and revoke connections when they are no longer needed.

DATA-HANDLING REVIEW

Resolve the operational questions early.

AreaWhat your evaluation should establish
Storage & retentionWhich original messages, detections, and audit records are retained; where they reside; how long they are kept; and how deletion and backups are managed.
Identity & accessWho can inspect session content, manage credentials, alter policy, author rules, and authorize an investigating AI. Confirm identity-provider requirements against the proposed release.
Provider processingWhich content is forwarded after transformation, which model provider receives it, and which provider terms apply.
AI-assisted investigationWhich reviewing model is permitted to receive evidence, how its credentials are controlled, and whether it may make corrective or rule changes.
ContinuityBehavior under scan failure, provider outage, timeout, database failure, and exhausted capacity. Validate the required fail-open or fail-closed behavior for each workflow.
ProcurementContract scope, pricing, support expectations, data-processing terms, deployment responsibilities, and any assurance evidence required by your organization.

CUSTOMER RELEASES

Verify what you deploy.

The customer-managed release process uses immutable image digests, signed artifacts, vulnerability scans, and software bills of materials. Offline detector model and compiled-rule packs support installations without runtime downloads of those assets.

Verification, secrets management, backups, monitoring, and upgrade execution remain concrete operating responsibilities. Ask for the evidence associated with the specific release you evaluate.

Review deployment responsibilities

Trust questions.

Is Milgram SOC 2 or ISO 27001 certified?

This site does not claim SOC 2 attestation or ISO 27001 certification. If your procurement process requires specific assurance documents, include those requirements in your evaluation request so the team can confirm what is available.

Does Milgram replace endpoint or infrastructure security?

No. AI traffic inspection complements least privilege, sandboxing, identity controls, network segmentation, application authorization, and incident response. It does not patch infrastructure vulnerabilities or undo actions that have already executed.

Can we use the beta with sensitive production data immediately?

First agree on data-processing terms, access controls, retention, deployment scope, and incident procedures. Begin validation with approved representative data and introduce production traffic only after your organization’s review.

INVITE-ONLY BETA

Bring your security requirements.

Discuss data handling, deployment responsibilities, and the assurance evidence your organization needs.

Talk to Milgram