Built for regulated industries. Verifiable, not just promised.
When you are accountable for the data, “trust us” is not enough. The A4 Platform is built so you can prove what happened, keep your data where your rules require it, and sign in with the identity provider you already run.
The platform shows exactly what was attempted and blocked — per person, per action, in real time.
Denied unless you allow it — resolved down your whole organization, per person.
Every action — by a person or an AI agent acting on their behalf — is checked against your permission rules before it happens. An agent can only ever touch what the person it acts for is allowed to touch, and nothing more.
Permissions resolve through your organization’s full hierarchy: a department inherits from a division, a division from the top, and individual overrides apply at any level. There is no way for “just ask the AI” to route around your controls — because the controls are enforced, not advised.
Your people get exactly what their role requires — and nothing beyond it.
Roles are configured at the organization level, not per person, so adding someone to the right group is all it takes. Remove the group membership and access ends — instantly, everywhere, with no manual cleanup list.
Roles, groups, and permission assignments — the full picture in one place.
Every decision is on the record — and the record can’t be quietly rewritten.
Most systems ask you to believe their logs. A4 lets you verify them.
Every action that matters — who was allowed to do what, what an AI agent did, every approval, every escalation, every change to a policy — lands in a single, continuous record. That record is built so that each entry is mathematically linked to the one before it. Alter, delete, or back-date a single entry — even directly in the database — and the chain breaks at exactly that point. A check run on demand pinpoints the first entry that was touched.
No quiet edits. No after-the-fact cleanup. When you tell an auditor what happened, you can show them — and they can confirm it without taking your word for it.
Isolated by organization. Encrypted in transit and at rest. We never train on your data.
Your data, your people, and your record stay inside your organization. Nothing crosses the boundary into anyone else’s account.
Walled off completely.
Each organization runs inside its own isolated boundary — enforced by construction at the database, query, and tool-handler layers, not by optional filters a developer could forget. Data is encrypted at rest with AES-256 via AWS KMS, and sensitive data is wrapped with a dedicated per-tenant key that rotates automatically, so every account is cryptographically separated. Traffic is encrypted in transit with TLS 1.2+, and protected health information gets an additional layer of application-level encryption on top. For strict cryptographic requirements, a dedicated FIPS-mode environment is available.
Your data is yours. Always.
Bring your own AI model and swap it whenever the market moves. The line we never cross: we never train on your data. It is used to serve you, and only you. Nothing you put into the platform leaves to improve a shared model.
The single sign-on you already run — Okta, Entra, Google, and others.
No new password to manage, no separate user list to keep in sync. A4 plugs into your existing sign-on, so your people authenticate the way they already do, under the access policies you already enforce.
Self-serve SAML 2.0 single sign-on and SCIM 2.0 provisioning are available to every organization, configured in your admin console, with OIDC federation supported. When someone joins, they are granted access automatically. When they leave, that access is removed automatically — no manual onboarding lists, no stale accounts lingering after an offboarding. You can also require multi-factor authentication (TOTP) for everyone in your organization through a single policy, so your directory stays the single source of truth.
Enterprise single sign-on on one page — SAML 2.0, domain routing, SCIM provisioning, and a full SAML auth log, configured in your own admin console.
Joiners provisioned, leavers deprovisioned — automatically.
Your identity provider drives the user list. A4 exposes a standards-based SCIM 2.0 endpoint (RFC 7644), protected by a bearer token you mint and rotate yourself — A4 stores only a hash of it, never the value. Turn on user and group sync and people are created, mapped to the right roles, and deactivated the moment your directory says so — no manual onboarding list, no stale account left behind.
Standards-based SCIM 2.0 provisioning — users and groups synced from your identity provider, with a bearer token you mint and rotate yourself.
Your directory groups become roles — and the rules that gate access.
Map an identity-provider group to a role, an organization, or the right to run an agent or persona — the grant stays inert until a matching person signs in or syncs. Conditional-access policies gate who can sign in and what an agent can dispatch, org-scoped and off by default until you turn them on. Every grant and every access decision is recorded, with the matched policy and the reason it applied.
Identity-provider groups mapped to roles and org membership, conditional-access policies gating sign-in and agent dispatch — every grant and decision on the record.
Built for the frameworks your industry holds you to.
Security and privacy are part of how A4 is built — with controls mapped to the SOC 2 Trust Services Criteria and the standards you are measured against, not bolted on after the fact.
A Business Associate Agreement, ready to sign.
Protected health information is encrypted, access is permission-controlled, and every touch is recorded. A Business Associate Agreement with our cloud provider is executed. Customer BAAs are available on request — no back-and-forth required.
Privacy rights handled, with the paperwork ready.
Collect only what is needed. Honor right-to-erasure, access, and portability requests across GDPR, CCPA, and LGPD. Generate Article 30 ROPA exports from your processing-activity register, and sign a Data Processing Addendum with Standard Contractual Clauses. Data-processing agreements are in place for every provider who touches your data.
Our controls map to the SOC 2 Trust Services Criteria — security, availability, processing integrity, confidentiality, and privacy. Need the detailed control mappings for a security or procurement review? Request our security overview and we will route it to the right team.
Data residency, resilience, and a clean exit — all built in.
Data residency is not a setting buried in a contract. You choose the region, and your data stays there.
Pick your region. We keep it running.
Each deployment runs in the cloud region you select, across multiple independent availability zones. For deployments whose primary region is in the United States, your data is continuously replicated to a second AWS region kept ready as a hot standby — so a regional outage is something you recover from, not something that stops you. Prefer to run it yourself? A self-hosted or on-premises deployment is available.
Export everything, anytime. No lock-in.
Your data belongs to you, and you can take it out whenever you want — not just at the end of a contract. Documents, records, audit logs, and compliance artifacts all export in standard formats your other systems can read. Every export is itself recorded, so you always have a clean account of who took what, and when.
The providers we use to run the platform — all named, all under agreement.
We are open about who touches your data. These are the providers we rely on to run A4 — each one under a formal data-processing agreement, and published as a live registry so every change is announced the moment it lands.
Bring your security team. We’ll show you the proof.
We are glad to walk your security, compliance, and procurement teams through how A4 protects your data — in as much depth as your review requires. Request our security overview, or bring your questions and we will answer them directly.
Healthcare BAA, data-processing agreement, or a vendor questionnaire to complete? Tell us the topic and we will route it to the right team.