FAQ
The questions a security review opens with, answered plainly. If yours is not here, ask it on the demo and we will answer it the same way.
What a security review asks
Six answers you can hold us to.
Control
What can the agent actually change in my environment?
By default, nothing. Every write is declared, scoped and separately enabled, and only what a playbook declares can run once you enable it. Read and write are separated at connector level, so a workflow that has not been given a write tool cannot acquire one.
Deployment
Do we have to send anything to your cloud?
No. CloudPeek runs where you put it, including fully disconnected. In a disconnected deployment there is no phone home, no telemetry, no licence check and nothing to reconnect.
Models
Which model does it use?
Whichever one you choose. Frontier, sovereign or CloudPeek’s own small language models inside your boundary. No external model call is required at any point, and the choice can differ by environment.
Integration
What if you do not support a tool we run?
Point the connector builder at its API specification. It drafts the tools, scopes the authentication, separates read from write and runs a security scan before anything joins your catalogue. Namespaced, versioned and sandboxed.
Assurance
What do we get for an audit?
Every investigation and action is a timestamped, append only record carrying its evidence and its reasoning. It maps to your control framework and exports for internal assurance, regulators and auditors, retained and disposed of on your schedule.
Adoption
How does a deployment usually start?
At level one, on a workflow you already understand, against real data in test. You move a workflow up a level when a body of clean runs says it is ready, and you can turn it back down at any time.




