Skip to content
CapitalSourceTrust & security
Security

Auditable by design.

CSG-1003 packages move money. Every architectural decision in CapitalSource.ai assumes that audit and isolation are non-negotiable. The controls below are enforced in code, not policy.

Status

What is running, and what is not.

Every claim on this site carries a build status, and this is where all of them are collected. The rows come from the same data the rest of the site renders from, so a page cannot promote something here without promoting it everywhere.

Live today
Built and ready. Setup, permissions, and runtime deployment requirements are tracked separately.
In build
Being built now. Design-partner slots only, and it is not self-serve.
Planned
Specified and not started. There is no code behind it yet.

Agents

  • IntakeLive today

    Runs the CSG-1003 conversation and produces a certified package.

  • ProcessorLive today

    Works the deal in a Slack channel — documents in, packaged file out.

  • CFOLive today

    A CFO-shaped agent for the merchant side of the table.

  • BookkeeperLive today

    Keeps the books current so the numbers a lender asks for already exist.

  • UnderwriterLive today

    Turns a submitted package into a citation-backed credit memo.

  • AnalystLive today

    Reads the financials and says what the numbers actually show.

  • MonitorerLive today

    Watches funded deals and raises a hand before a problem becomes a default.

  • EvaluatorLive today

    Grades the other agents against a rubric before a customer sees the output.

  • ComplierLive today

    Checks the file against the rules before it leaves the building.

  • MarketeerLive today

    Runs the outbound that keeps the pipeline full.

  • RegTrackerLive today

    Tracks rule changes across the states you lend in and flags what they affect.

Billing rails

  • OriginationsLive today

    Certified dispatches are counted and priced. Subscriptions are set up by us — there is no self-serve plan change.

  • InvocationsLive today

    2 of 7 registered capabilities do real work; the rest return a pending stub and say so before you are billed.

  • DeploymentsIn build

    Built agents are configured per engagement. Setup and recurring deployment costs are quoted, with runtime availability checked separately.

  • ReviewsPlanned

    No meter, no counter, and no read path. The only reader of a certified package filters on the caller’s own organization, so the billable event cannot occur yet.

  • CheckoutPlanned

    Not built. There is no plan picker, no card entry and no invoice history anywhere in the product — nothing on this site can charge you.

Connectors

  • SlackLive today

    Connectable from the portal and usable in a flow.

  • WhatsAppLive today

    Connectable from the portal and usable in a flow.

  • Google ChatLive today

    Connectable from the portal and usable in a flow.

  • TelegramLive today

    Connectable from the portal and usable in a flow.

  • iMessagePlanned

    Defined in the catalog and not connectable.

Surfaces

  • Web portalLive today

    Applications, flows, knowledge, agents, settings.

  • REST APILive today

    Versioned at /v1, documented by the OpenAPI file in the repo.

  • MCP serverLive today

    Fourteen tools over stdio today; the HTTP transport is built and has no public hostname.

  • Recurser CLILive today

    Private at 0.0.0 and unpublished, so you build it from the repo.

  • Hosted agent deploymentIn build

    The wizard checks for a released runtime image and deployment permissions. Built-agent status alone does not bypass those requirements.

  • Funder portalPlanned

    There is no cross-organization read path, which is what the Reviews rail would bill for.

  • Self-serve billingPlanned

    Plan changes, spend-cap changes and invoices are handled directly by us.

If something on this page and something on another page disagree, this one is right — tell us and we will fix the other.

Controls

Enforced in code

Seven load-bearing controls. Each has a corresponding test or lint rule that fails CI if broken.

Tenant isolation

All database access goes through lib/db/tenant-scope.ts. ESLint blocks any prisma call without an organization_id filter. Every tenant-scoped endpoint has an isolation test that asserts wrong-org access returns 404 or 403.

Append-only audit log

The audit_logs table is write-once and only domain/audit/log.ts (logAudit) can write to it. The ESLint rule no-restricted-syntax blocks any other code path from calling prisma.auditLog.create / update / delete.

Ed25519-signed packages

Every certified CSG-1003 package is signed with an Ed25519 key held as a deployment secret (CERTIFICATION_SIGNING_KEY) — never stored beside the object it signs. The public half is published as a JWKS at /.well-known/capitalsource-trust.json, so anyone holding a package can verify it independently. There is no funder import path yet; verification today is something a recipient does with the JWKS, not a product feature.

Encryption at rest and in transit

TLS 1.3 to all surfaces. Database storage encrypted at rest by DigitalOcean Managed Postgres. Secret material (Stripe keys, OAuth secrets, model provider keys) lives in DO secret-keeper, never in source control or environment variable dumps.

Provider-key isolation

LLM provider SDKs are only imported in lib/ai/providers/. The router enforces forced failover and per-tenant routing rules. Tenants can bring their own provider keys without sharing them with other tenants.

Spend caps at the gateway

Every model call is priced and counted in the same transaction that records the response, and a tenant over its cap is refused at the gateway rather than warned afterwards. The cap is enforcement-only today: it is visible in the portal but there is no self-serve control to change it, so a change is a conversation with us.

Inbound webhook verification

Stripe webhooks are signature-verified with a replay-tolerance window, then persisted inside a transaction and deduplicated on the provider event id, so a redelivery cannot double-apply. Outbound tenant webhooks are designed — tables and HMAC secret storage exist — but the dispatcher is not built yet, so do not plan on receiving callbacks today.

CapitalSource Agent Harness

Saved progress. Explicit approvals.

The execution layer that keeps agent work moving—with scoped permissions, spending limits, and a record of the task. Starting with the Processor application-readiness pilot in Flows.

Preview before deliveryStart in shadow mode to inspect readiness evidence and proposed operations follow-ups without sending a message.

Approve the exact actionEach Slack delivery requires approval of the message and destination. Permissions and supporting evidence are checked again before dispatch.

Follow the same taskSee progress and model spending as application information changes. Reassess or cancel a task from its run detail.

Workspace setup is required. Broader fleet support is planned; the pilot assesses readiness and prepares operations follow-ups. Financing decisions remain with people.

Hosted agents

What isolation means when we run the agent

The finance agents are built. A hosted deployment also requires a released runtime image and configured infrastructure. These are the isolation boundaries to review before enabling a deployment for your organization.

One tenant per instance

A deployed agent gets its own container and its own volume. No shared container, volume, or secret store between organizations, and none between a customer instance and anything internal.

Per-instance egress policy

A firewall bound to a tag created before the host exists, so there is no window where the instance is reachable or unrestricted. It can reach Slack and our API; it has no inbound ports at all.

No provider credentials on the instance

The agent cannot call a model provider directly. Every model call goes through our gateway with an instance-scoped credential, which is what makes spend caps and usage records unavoidable rather than best-effort.

Secrets delivered once

Credentials are fetched at first boot with a single-use token and never baked into an image. Images carry code and dependencies only — CI scans every layer for credentials, transcripts, and customer documents.

A deployment record per instance

Image digest, spec commit, config hash, and secret-set version are recorded on every change, so “what exactly is this customer running?” has an answer during an incident and the instance can be rebuilt from it.

Telemetry stays tenant-scoped

An agent reports task outcomes and health to us, not deal contents. Customer conversation data stays on the customer’s own volume and is not mirrored into shared internal telemetry.

Session transcripts on a customer volume are customer data. Data-return and deletion terms for hosted deployments are being finalised with counsel before the first external instance — ask us for the current draft.

Compliance & data sovereignty

Tracked, not asserted.

We are honest about what is certified vs. what we align to. Regulation moves; the controls below reflect our current posture against each regime and the disclosures that surface in the §4 cross-cutting layer of every CSG-1003 application.

GDPR

tracking
EU

Designed against data-subject rights, not yet automated. There is no self-serve export endpoint and no erasure endpoint — access, portability, and deletion requests are handled manually by our team at privacy@capitalsource.ai. Purpose specification and consent tracking flow through the §4 cross-cutting blocks of CSG-1003. Standard DPA available on request.

EU AI Act

tracking
EU

CSG-1003 itself is a structured-data protocol, not a "high-risk" AI system. We track the act's transparency + copyright requirements for any general-purpose AI features deployed into EU markets. Tenants in the EU receive model-training and provenance disclosures.

SEC AI guidance

tracking
US

We monitor the SEC AI Task Force's evolving guidance for any rulings touching broker / funder use of AI in credit decisioning. Disclosures land in the same §4 cross-cutting layer.

US state AI laws

tracking
US (state)

CO SB-205, IL HB-3773, NYC Local Law 144, CA SB-942, TX HB-2060 — state-level provisions touching AI-driven credit decisioning, automated employment decisions, and chatbot disclosure flow through CSG-1003 §4 disclosure blocks where applicable.

SOC 2 Type 1

in progress
US

Evidence-collection underway. The append-only audit log, tenant-isolation gate, and Stripe-reconciled usage records are all designed against the SOC 2 control families.

We are not currently certified under GDPR or ISO/IEC 42001. Specific tenant-grade attestations (HIPAA, PCI scope, state lending licenses) are scoped per-deal. Contact sales for a compliance questionnaire.

AI security frameworks

Four frameworks. Different lenses.

No single framework covers every layer — governance, application security, and adversarial threat modeling each need their own. We use all four as design inputs and audit references, not marketing badges.

  • NIST AI RMF
    NIST AI Risk Management Framework
    Governance, lifecycle risk, organizational controls
    We organize internal AI risk management against the four functions (Govern, Map, Measure, Manage). The Generative AI Profile informs our LLM router design and per-tenant routing rules.
  • ISO/IEC 42001
    AI Management System Standard
    Formal AI governance, accountability, continual improvement
    Tracked as the eventual certification target. Our governance processes — incident response, change management, model-card maintenance — are organized to support a future audit.
  • OWASP LLM Top 10
    OWASP Top 10 for LLM Applications
    Application-layer security for LLM/genAI
    Prompt-injection defenses, tool-use allow-listing, output filtering, and the per-(org, capability) rate-limit isolation gate map directly to the OWASP LLM Top 10 risks. We have not commissioned an external red-team engagement, so treat this as a design input rather than a tested result.
  • MITRE ATLAS
    Adversarial Threat Landscape for AI Systems
    AI-specific threat modeling, adversary TTPs
    ATLAS is the taxonomy we reason with when we design against agent-specific attacks — evasion, poisoning, exfiltration. We have not published a threat model against it and there is no document to request; this is a reference we use, not an artefact we can show you.
Responsible disclosure

Report a vulnerability

Email security@capitalsource.ai with a description of the issue and steps to reproduce. We commit to:

  • Do not exfiltrate tenant data or access another tenant’s applications.
  • Do not run brute-force or automated scanning against production endpoints.
  • Allow up to 7 business days for an initial response.
  • We do not currently run a paid bug-bounty program but recognize valid reports publicly with permission.