Tenant isolation
All database access goes through lib/db/tenant-scope.ts. ESLint blocks any prisma call without an organization_id filter. Every tenant-scoped endpoint has an isolation test that asserts wrong-org access returns 404 or 403.
CSG-1003 packages move money. Every architectural decision in CapitalSource.ai assumes that audit and isolation are non-negotiable. The controls below are enforced in code, not policy.
Every claim on this site carries a build status, and this is where all of them are collected. The rows come from the same data the rest of the site renders from, so a page cannot promote something here without promoting it everywhere.
Runs the CSG-1003 conversation and produces a certified package.
Works the deal in a Slack channel — documents in, packaged file out.
A CFO-shaped agent for the merchant side of the table.
Keeps the books current so the numbers a lender asks for already exist.
Turns a submitted package into a citation-backed credit memo.
Reads the financials and says what the numbers actually show.
Watches funded deals and raises a hand before a problem becomes a default.
Grades the other agents against a rubric before a customer sees the output.
Checks the file against the rules before it leaves the building.
Runs the outbound that keeps the pipeline full.
Tracks rule changes across the states you lend in and flags what they affect.
Certified dispatches are counted and priced. Subscriptions are set up by us — there is no self-serve plan change.
2 of 7 registered capabilities do real work; the rest return a pending stub and say so before you are billed.
Built agents are configured per engagement. Setup and recurring deployment costs are quoted, with runtime availability checked separately.
No meter, no counter, and no read path. The only reader of a certified package filters on the caller’s own organization, so the billable event cannot occur yet.
Not built. There is no plan picker, no card entry and no invoice history anywhere in the product — nothing on this site can charge you.
Connectable from the portal and usable in a flow.
Connectable from the portal and usable in a flow.
Connectable from the portal and usable in a flow.
Connectable from the portal and usable in a flow.
Defined in the catalog and not connectable.
Applications, flows, knowledge, agents, settings.
Versioned at /v1, documented by the OpenAPI file in the repo.
Fourteen tools over stdio today; the HTTP transport is built and has no public hostname.
Private at 0.0.0 and unpublished, so you build it from the repo.
The wizard checks for a released runtime image and deployment permissions. Built-agent status alone does not bypass those requirements.
There is no cross-organization read path, which is what the Reviews rail would bill for.
Plan changes, spend-cap changes and invoices are handled directly by us.
If something on this page and something on another page disagree, this one is right — tell us and we will fix the other.
Seven load-bearing controls. Each has a corresponding test or lint rule that fails CI if broken.
All database access goes through lib/db/tenant-scope.ts. ESLint blocks any prisma call without an organization_id filter. Every tenant-scoped endpoint has an isolation test that asserts wrong-org access returns 404 or 403.
The audit_logs table is write-once and only domain/audit/log.ts (logAudit) can write to it. The ESLint rule no-restricted-syntax blocks any other code path from calling prisma.auditLog.create / update / delete.
Every certified CSG-1003 package is signed with an Ed25519 key held as a deployment secret (CERTIFICATION_SIGNING_KEY) — never stored beside the object it signs. The public half is published as a JWKS at /.well-known/capitalsource-trust.json, so anyone holding a package can verify it independently. There is no funder import path yet; verification today is something a recipient does with the JWKS, not a product feature.
TLS 1.3 to all surfaces. Database storage encrypted at rest by DigitalOcean Managed Postgres. Secret material (Stripe keys, OAuth secrets, model provider keys) lives in DO secret-keeper, never in source control or environment variable dumps.
LLM provider SDKs are only imported in lib/ai/providers/. The router enforces forced failover and per-tenant routing rules. Tenants can bring their own provider keys without sharing them with other tenants.
Every model call is priced and counted in the same transaction that records the response, and a tenant over its cap is refused at the gateway rather than warned afterwards. The cap is enforcement-only today: it is visible in the portal but there is no self-serve control to change it, so a change is a conversation with us.
Stripe webhooks are signature-verified with a replay-tolerance window, then persisted inside a transaction and deduplicated on the provider event id, so a redelivery cannot double-apply. Outbound tenant webhooks are designed — tables and HMAC secret storage exist — but the dispatcher is not built yet, so do not plan on receiving callbacks today.
The execution layer that keeps agent work moving—with scoped permissions, spending limits, and a record of the task. Starting with the Processor application-readiness pilot in Flows.
Preview before deliveryStart in shadow mode to inspect readiness evidence and proposed operations follow-ups without sending a message.
Approve the exact actionEach Slack delivery requires approval of the message and destination. Permissions and supporting evidence are checked again before dispatch.
Follow the same taskSee progress and model spending as application information changes. Reassess or cancel a task from its run detail.
Workspace setup is required. Broader fleet support is planned; the pilot assesses readiness and prepares operations follow-ups. Financing decisions remain with people.
The finance agents are built. A hosted deployment also requires a released runtime image and configured infrastructure. These are the isolation boundaries to review before enabling a deployment for your organization.
A deployed agent gets its own container and its own volume. No shared container, volume, or secret store between organizations, and none between a customer instance and anything internal.
A firewall bound to a tag created before the host exists, so there is no window where the instance is reachable or unrestricted. It can reach Slack and our API; it has no inbound ports at all.
The agent cannot call a model provider directly. Every model call goes through our gateway with an instance-scoped credential, which is what makes spend caps and usage records unavoidable rather than best-effort.
Credentials are fetched at first boot with a single-use token and never baked into an image. Images carry code and dependencies only — CI scans every layer for credentials, transcripts, and customer documents.
Image digest, spec commit, config hash, and secret-set version are recorded on every change, so “what exactly is this customer running?” has an answer during an incident and the instance can be rebuilt from it.
An agent reports task outcomes and health to us, not deal contents. Customer conversation data stays on the customer’s own volume and is not mirrored into shared internal telemetry.
Session transcripts on a customer volume are customer data. Data-return and deletion terms for hosted deployments are being finalised with counsel before the first external instance — ask us for the current draft.
We are honest about what is certified vs. what we align to. Regulation moves; the controls below reflect our current posture against each regime and the disclosures that surface in the §4 cross-cutting layer of every CSG-1003 application.
Designed against data-subject rights, not yet automated. There is no self-serve export endpoint and no erasure endpoint — access, portability, and deletion requests are handled manually by our team at privacy@capitalsource.ai. Purpose specification and consent tracking flow through the §4 cross-cutting blocks of CSG-1003. Standard DPA available on request.
CSG-1003 itself is a structured-data protocol, not a "high-risk" AI system. We track the act's transparency + copyright requirements for any general-purpose AI features deployed into EU markets. Tenants in the EU receive model-training and provenance disclosures.
We monitor the SEC AI Task Force's evolving guidance for any rulings touching broker / funder use of AI in credit decisioning. Disclosures land in the same §4 cross-cutting layer.
CO SB-205, IL HB-3773, NYC Local Law 144, CA SB-942, TX HB-2060 — state-level provisions touching AI-driven credit decisioning, automated employment decisions, and chatbot disclosure flow through CSG-1003 §4 disclosure blocks where applicable.
Evidence-collection underway. The append-only audit log, tenant-isolation gate, and Stripe-reconciled usage records are all designed against the SOC 2 control families.
We are not currently certified under GDPR or ISO/IEC 42001. Specific tenant-grade attestations (HIPAA, PCI scope, state lending licenses) are scoped per-deal. Contact sales for a compliance questionnaire.
No single framework covers every layer — governance, application security, and adversarial threat modeling each need their own. We use all four as design inputs and audit references, not marketing badges.
Email security@capitalsource.ai with a description of the issue and steps to reproduce. We commit to: