Trust at Versalist
Understand where your agent runs, how API access works, and what an evaluation records.
Where your agent runs
Hosted model-only evaluation, local-model answers submitted for judging, and entirely local CLI records have different execution and data boundaries. Python sandbox implementation still needs hosted validation. The execution guide explains what each option requires and how results are recorded.
API access and credentials
New-account API access requires admin approval. Use scoped API keys to control access from your integrations. The API key guide explains how to create and revoke keys. Provider credentials have a separate setup guide.
What traces record
When enabled, trace capture records call metadata to help you inspect a run. Coverage depends on the execution path and configuration. A trace may not contain every event. Metadata-only capture does not mean that episode outputs, evaluator text or saved private inputs are not stored elsewhere.
Current procurement status
Documentation explains supported paths and limitations; it is not an independent certification or a guarantee for every deployment. Unknowns stay open until the responsible owner verifies them.
- Where does the agent run and what is recorded?
- Documented · Read the documentation and limits
- What call metadata is captured and what are its limits?
- Documented · Read the documentation and limits
- How are API keys scoped and revoked?
- Documented · Read the documentation and limits
- How are customer model-provider credentials handled?
- Documented · Read the documentation and limits
- Hosting regions and encryption statements
- Not yet verified · Pending approved provider inputs
- Subprocessor inventory
- Not yet verified · Pending approved provider inputs
- Artifact retention and backup deletion
- Not yet verified · Pending retention and deletion review
- Approved security contact
- Not yet verified · Pending named contact
- Contractual service levels and certification evidence
- Not yet verified · Pending contract terms; no certification is claimed
- SAML or OIDC single sign-on
- Not offered · Google, GitHub, and invite links are the supported sign-in paths
Company-managed provider keys and allowlists are unavailable. Individual BYOK is separate. Private challenge libraries do not establish a private VPC or on-premises deployment. DPA and MSA requirements are reviewed during scoping; no approved agreement or certification is implied.
Questions from your security team?
Include your requirements for hosting regions, subprocessors, data retention, or service terms when you request a security review.
Request a security review