Safe for every team. Ready for the enterprise.
An agent that can act on your systems is only as safe as the boundaries around it. Keep people, agents, tools, and runs inside clear boundaries, and add organization-wide governance and your preferred deployment model as you scale.
Four boundaries, enforced separately
Access is not one switch. Each of these is enforced on its own, so no single one failing quietly grants the rest.
Secure deployment
Deploy in single tenancy, inside your own VPC, or fully on-premise, in the region you choose. It can run completely air-gapped, with no third parties.
LLM provider safety
API keys never enter the sandbox, and model traffic passes through one audited egress point. A self-hosted model keeps everything in-house.
Sandboxed execution
Every run gets its own sealed workspace, destroyed when it's done. Outbound traffic follows the policies you set, and credentials are injected into the calls that leave, so keys never touch the sandbox.
SSO & access control
Plug into the identity provider your team already uses. Set who can run what, and every read, write, and decision is logged for audit.
You stay in the loop
Nothing consequential happens without a person. Approvals are scoped, they expire, and every run stays on the record.
Approvals expire
A once approval lasts 15 minutes and one matching call. A session approval, at most 24 hours. Neither changes long-term policy.
Retrieved content cannot give orders
A document is evidence, never permission. Unattended runs report the instructions they find. They do not follow them.
Every run on the record
Tool calls, approvals, files, and failures are all retained. Automatic actions are logged separately from approved ones.
Your data stays in your region
We run d5s from regional cells, one in the EU and one in the US. Your workspace data lives in its cell, with its own AWS account, database, object storage, encryption keys, and backups, so a region is a boundary rather than a label on a form. Some supporting services are global rather than per-region; the customer agreement sets out the full picture.
You can also run d5s yourself: in single tenancy, inside your own VPC, or fully on-premise in the region you choose, including completely air-gapped with no third parties. Scope is set in the customer agreement.
