Security at ContactLab

The execution boundary is part of the product.

ContactLab is designed to keep agent work within boundaries defined by the organization. This page separates the designed control model from the assurance status that can be confirmed today.

Current assurance status

The controls below describe ContactLab's designed model. Runtime disposal, network-policy enforcement, credential injection and revocation, encryption, retention and tenant separation require technical and contractual verification for the applicable deployment before they are treated as operating guarantees. This page does not claim independent audit or certification of those controls.

Designed control model

Execution isolation

In the designed model, agent work runs in task-scoped, ephemeral environments. Each run should start from a defined base, receive resources through its execution profile and dispose of the environment when the task ends. Effective disposal and environment separation require verification for the applicable deployment.

Network

In the designed model, execution-profile policy restricts network egress. Approved destinations and resource paths are defined before a run, and attempts outside policy should produce blocked events. The configuration and effectiveness of these controls must be verified for each deployment.

Secrets and identity

In the designed model, credentials are scoped to the workflow instead of inherited from a user workstation. Secrets should be injected during the run and revoked when it ends according to the configured scope. Injection, revocation and the absence of persistent credentials require verification for the applicable deployment.

Data lifecycle

The model provides for prompts, execution events, policy decisions, artifacts and review outcomes to be retained as structured, tenant-scoped evidence. Retention and deletion are set by contract and must be verified for the deployment; this page guarantees no default retention period.

Encryption

The model provides for TLS in transit and managed-key encryption at rest. The effective configuration, key management and any dedicated-deployment options must be confirmed in the technical and contractual scope.

Identity and access

The model provides for per-user authentication and role-based administration for platform administrators, reviewers and end users. Effective roles, SSO and directory integration must be confirmed during scoping.

Tenancy

The model is designed to scope identity, execution profiles, policies and evidence to each tenant through the control plane. The effectiveness of tenant separation must be verified for the applicable deployment before it is treated as an operating guarantee.

Subprocessors

ContactLab runs on cloud infrastructure providers and uses model providers (Anthropic and OpenAI) for the supported agents. The current subprocessor list is provided during enterprise scoping and kept current as it changes.

Compliance

ContactLab is not currently SOC 2 or ISO 27001 certified. Current assurance depends on the controls, evidence review and contractual terms agreed for each pilot. We will update this page when an independent audit is complete.

Vulnerability reporting

Report suspected vulnerabilities to jorleyoliveira@contactlabsolutions.com. Include reproduction details where possible; we acknowledge reports and coordinate fixes with reporters.

See ContactLab at work.

During the meeting, we show a live or prepared governed execution in ContactLab's own company environment. You can inspect the configured boundaries, a human-review record and the evidence available after the run.