Scoped administration
User capabilities and authorized scopes constrain the actions exposed through the API and MCP. Separate investigation access from permissions to change rules or policies.
SECURITY & TRUST
Understand the data Milgram handles, the controls around access, and the responsibilities to establish before a production rollout.
KNOW WHAT THE BOUNDARY HOLDS
Milgram handles AI traffic and session records that may contain sensitive information. Treat that data as part of your security architecture.
The proxy inspects original client content. Policy masking and compression can transform what is forwarded to a model provider, while inspection and audit paths can retain the original input. Masking is therefore not a claim of zero storage or zero visibility inside Milgram.
During evaluation, map the complete data path: client, proxy, worker, persistence, provider, dashboard, and any external AI used for investigation. Establish who can access the evidence and what processing is allowed at each point.
Customer-managed deployment places operating responsibilities in your environment. A hosted evaluation needs its own agreed data-handling and service boundaries.
IMPLEMENTED CONTROLS
User capabilities and authorized scopes constrain the actions exposed through the API and MCP. Separate investigation access from permissions to change rules or policies.
The authentication implementation includes TOTP multi-factor enrollment and recovery-code flows. Confirm the enrollment and administrative practices appropriate to your deployment.
Connected MCP clients receive scoped authorization. Review their granted access and revoke connections when they are no longer needed.
DATA-HANDLING REVIEW
| Area | What your evaluation should establish |
|---|---|
| Storage & retention | Which original messages, detections, and audit records are retained; where they reside; how long they are kept; and how deletion and backups are managed. |
| Identity & access | Who can inspect session content, manage credentials, alter policy, author rules, and authorize an investigating AI. Confirm identity-provider requirements against the proposed release. |
| Provider processing | Which content is forwarded after transformation, which model provider receives it, and which provider terms apply. |
| AI-assisted investigation | Which reviewing model is permitted to receive evidence, how its credentials are controlled, and whether it may make corrective or rule changes. |
| Continuity | Behavior under scan failure, provider outage, timeout, database failure, and exhausted capacity. Validate the required fail-open or fail-closed behavior for each workflow. |
| Procurement | Contract scope, pricing, support expectations, data-processing terms, deployment responsibilities, and any assurance evidence required by your organization. |
CUSTOMER RELEASES
The customer-managed release process uses immutable image digests, signed artifacts, vulnerability scans, and software bills of materials. Offline detector model and compiled-rule packs support installations without runtime downloads of those assets.
Verification, secrets management, backups, monitoring, and upgrade execution remain concrete operating responsibilities. Ask for the evidence associated with the specific release you evaluate.
Review deployment responsibilitiesThis site does not claim SOC 2 attestation or ISO 27001 certification. If your procurement process requires specific assurance documents, include those requirements in your evaluation request so the team can confirm what is available.
No. AI traffic inspection complements least privilege, sandboxing, identity controls, network segmentation, application authorization, and incident response. It does not patch infrastructure vulnerabilities or undo actions that have already executed.
First agree on data-processing terms, access controls, retention, deployment scope, and incident procedures. Begin validation with approved representative data and introduce production traffic only after your organization’s review.
INVITE-ONLY BETA
Discuss data handling, deployment responsibilities, and the assurance evidence your organization needs.