
Security, residency and model risk — published, not gated.
Written for the person who has to sign off. Where we do not yet hold a standard, that is stated here too, with the date. Last updated 6 September 2026.
In an on-premise deployment, nothing leaves.
No document leaves the perimeter. No file trains a shared model. Only configuration and telemetry cross the boundary, outward.
No outbound path for content
Documents and extracted data never cross your network boundary.
Inference inside your walls
Open-weight models on your hardware. No third-party provider receives your content.
No training by default
Nothing improves anything outside your instance without a written data-rights agreement.
Retention you control
Configurable to your schedule, including regulator-mandated holds.
Provenance on every action
Document, page, model, version, rule, timestamp, human.
The question behind the question
Anyone can run on-premise now. Ask whether the governance stack survives the move. Ours is the same system.
Where we stand, as of 6 September 2026.
A true status on every row. Every production customer will take a reference call; the closest to your situation is arranged in the first conversation.
| Item | Status | Detail |
|---|---|---|
| SOC 2 Type I | In progress | Report targeted November 2026. Bridge letter on request from that date. |
| SOC 2 Type II | Scheduled | Observation window starts after Type I. Report targeted mid-2027. |
| Penetration testing | Scheduled | First third-party test late 2026; summary under NDA, annually. |
| ISO 27001 | Planned | Programme begins after SOC 2 Type II. |
| Access control | Available | RBAC, SSO, approval gates per process step. |
| Audit logging | Available | Immutable, exportable log of every agent action and human intervention. |
| On-premise deployment | In production | Running today at a top-tier commercial bank on its own hardware. |
| Sandbox isolation | Available | Dedicated kernel + eBPF, <60 ms boot. |
| Proxy for agent egress | In production (internal) | Customer GA 2027. |
Built to be reviewed by people whose job is to say no.
Model-risk management, not model marketing.
Confidence scoring
Every field, every decision, configurable thresholds.
Evaluation harness
Quality measured, not asserted.
Approval gates
A human wherever your policy requires a signature.
Decision lineage
Document, page, model, version, rule, reviewer.
Bounded autonomy
No action outside the scope defined for each process.
Intellectual property
Patent application filed. Your data and corrections remain yours.
Privacy, briefly.
This site sets no advertising cookies. We measure how it is used with PostHog — pages, clicks, scroll depth and page speed — which sets a first-party cookie; nothing you type is recorded and there is no screen recording. This site does not respond to Do Not Track signals. The only personal data we collect is what you submit through the contact form — stored in our own Cloudflare account, read by our team, deleted on request. None of this applies to your deployment: what happens on this website and what happens inside a Densery instance are different systems, and no customer document ever reaches either. Fonts load from Google Fonts. The full privacy notice →
Security questionnaires, in 48 hours.
Send it. We will not ask for a call first. A maintained answer library covering the common frameworks. Architecture, data-flow diagrams, sub-processor list, BCP and incident response available under NDA.
Thirty minutes with Densery.
Tell us about the work you want an agent to finish. We listen first, then show you the platform and the case that is closest to yours. This is a working session, not a sales pitch.