Give the agent reach.
Keep control of
the boundary.
Centra puts encryption, identity, permissions, approvals, and evidence around the agent so access remains deliberate and consequential actions remain answerable to you.
The important limits live outside the prompt.

Durable state is encrypted
User state is protected by envelope encryption through Vault, scoped per user. Value-moving actions require one of two things: authority granted in advance, or a signed approval from you in the moment. There is no third path.
Approvals live in the execution model
Sensitive writes, external side effects, and financial actions stop and wait for a human. The gate is enforced in the execution model itself (the durable action lifecycle), not in a prompt. A clever instruction cannot talk its way past a gate that is not made of words.
Evidence, not performance
Every step an agent takes is written to a durable evidence log as it happens. Claims keep their provenance, and finished work carries the tool activity, checkpoints, and verification needed to tell a convincing answer from completed work.
Gideon receives one private environment per user
Each Gideon user gets a dedicated agent environment and a durable state boundary. Workmates uses a separate account-isolated model in which that user's teammates share one computer; access on that computer is available to all of that user's Workmates.
What leaves the system, and what never does.
Information filters
Agent outputs pass through filters that scrub internal configuration and secrets before anything reaches a user or a tool. What the platform knows about itself stays inside the platform.
Independent verification
Evidence-sensitive review stays separate from the claim being reviewed. Unproven work cannot turn itself into verified completion merely by sounding confident.
Memory holds no secrets
Agent memory stores your work and your preferences, never credentials. Model-provider access and metering sit at the gateway, so provider secrets never need to live inside a user's environment.
Publish the framework. Earn the certification.
Our AML/KYC policy, EU AI Act posture, compliance statement, and regulatory overview are public. Product availability does not imply a certification we have not earned.
AML / KYC policy
How we identify who we work with and what we screen for, published in full before we onboard the first paying customer.
EU AI Act compliance
Where Centra sits under the Act, the obligations that follow, and how our architecture meets them.
Compliance statement
Our standing statement of compliance posture, alongside a regulatory overview of the frameworks we track.
How we evaluate safety, govern agent behavior, and report on both lives in the transparency hub.
Visit the hubTell us which data, account, action, or approval boundary matters to your work. We will explain how the current product handles it.
