Skip to content
HumanLayer
Problem Arbitrium Solution Use cases API Pricing Become a Sentinel FAQ
FR EN
Client portal Get started
Problem 01 Arbitrium 02 Solution 03 Use cases 05 API 06 Pricing 08 Become a Sentinel → FAQ → Client portal →
FR EN
Get started now
← Back to home
Security

Security

Enterprise-grade controls protect every decision and every sensitive dataset processed by HumanLayer.

Last updated: September 2026 humanlayer@probalink.com

HumanLayer handles decisions that commit professionals and organizations. This page describes the measures actually in place; it is updated whenever they change.

Infrastructure

  • Encryption in transit: all traffic uses HTTPS (TLS 1.2 and above, TLS 1.3 when the browser supports it), with HSTS.
  • Secrets encrypted at rest: two-factor secrets are encrypted with AES-256-GCM; API keys are stored only as SHA-256 fingerprints; passwords are hashed with scrypt.
  • Hosting: SOC 2 Type II certified cloud infrastructure. Server code is not published with the website.
  • Isolation: each API key only reaches its own requests, each client only its keys and decisions, each Sentinel only the cases assigned to them.
  • Browser: strict Content Security Policy, framing forbidden, portals excluded from indexing.

Authentication and access

  • Two-factor authentication (TOTP) required for every Sentinel: it cannot be disabled, only renewed, and a code that was already used is rejected.
  • Administrator access protected by a password and a mandatory second factor.
  • Separate roles (administration, Sentinels, clients), each with its own session signing secret.
  • Sessions last 12 h at most, with automatic logout; the account status is checked on every request, so a suspension takes effect immediately.
  • Attempt limits: temporary lockout after 5 failed logins on an account, plus limits per IP address and per API key.
  • Audit log of logins and sensitive actions (decisions, API keys, authorizations, two-factor changes), exportable.

Decision integrity

  • Every decision is signed (Ed25519): identifiers, verdict, fingerprint of the justification, Sentinel pseudonym and timestamp. The public key is published (/api/v1/decision-key): any tampering is detectable.
  • A single final decision per request, recorded atomically.
  • Signed webhooks (HMAC-SHA256, secret specific to each API key); callback URLs limited to HTTPS and public hosts.
  • SLAs monitored continuously: any breach is reported and the request is reassigned automatically.

Sentinel verification

  • Identity verification before activation
  • Validation of professional qualifications and authorizations
  • Suspension possible at any time, effective immediately
  • Full traceability of each decision

Regulatory compliance

  • GDPR (General Data Protection Regulation)
  • Law 25 (Quebec)
  • SOC 2 Type II (certification in progress)
  • ISO 27001 (planned)

Vulnerability reporting

If you discover a security vulnerability, write to us at humanlayer@probalink.com. We commit to handling any report within 24 hours.

Testing and reviews

  • Automated tests of authentication, two-factor authentication, attempt limits, decision signatures and data isolation, run on every change.
  • Security review of the code (latest: September 2026).
  • Penetration testing by an independent third party: planned.
HumanLayer

The decision authority layer for AI agents.

HumanLayer Systems Inc.
1250, avenue de la Station, Shawinigan, Quebec G9N 8K9, Canada
humanlayer@probalink.com

Product

  • Arbitrium
  • Solution
  • Use cases
  • Pricing

Developers

  • API documentation
  • Developer FAQ
  • Client portal

Network

  • Become a Sentinel
  • Sentinel portal
  • Sentinel FAQ

Company

  • FAQ
  • Security
  • Privacy
  • Terms
  • Contact
HumanLayer
© 2026 HumanLayer Systems Inc. All rights reserved. Designed in Quebec · Version française Powered by in6.ai