Andus early access — meet your agency’s first AI teammate →
Security/ how isolation holds

Isolation is the architecture.

No badges, no acronym wall — the five mechanisms that keep agencies, their clients, and their agents inside their own walls.

Tenancy

Isolation, enforced twice.

At the database and on every request — row-level security and role-gated routes. Agencies and their clients never see each other’s data.

Sessions

Host-isolated by design.

Branding and sessions follow the hostname. A login on one partner’s portal can never cross to another.

Credentials

An encrypted vault.

Encrypted at rest with AES-256-GCM, decrypted server-side only, retrieved by scope. Keys are never returned to the browser.

Access

Eleven roles, audited.

Each teammate gets exactly what their job needs. One-click “view as client” for support is fully audited, like everything else.

Agents

Agents under the same law.

Andus acts through platform roles, never Slack channels. No publish, spend, or credentials without confirmation — every request logged, including denials.

Compliance

SOC 2 is in progress.

Ask us where we are today — we’ll share our current status and roadmap.

Audit log — AndusIMMUTABLE · INCLUDES DENIALS
TimeActorModeActionScopeResult
09:41JordanRetrievemeta.insights.pullclient/horizon-med-spaOK
09:42JordanActtasks.create · confirmedclient/horizon-med-spaOK
11:05PriyaReportmeetings.summaryclient/cedar-dentalOK
13:18ColeActcampaigns.publishclient/summit-hvacDENIED · role lacks publish
16:30systemMonitorintegrations.healthorg/apex-digitalOK
Every request lands in the log — including the ones Andus refuses
The full trust & isolation section lives on Integrations →

Stop running tools. Start running an agency.

Get started
Your keys, your permissions, your control plane