Trust at Versalist

Understand where your agent runs, how API access works, and what an evaluation records.

Where your agent runs

Hosted model-only evaluation, local-model answers submitted for judging, and entirely local CLI records have different execution and data boundaries. Python sandbox implementation still needs hosted validation. The execution guide explains what each option requires and how results are recorded.

Compare execution options

API access and credentials

New-account API access requires admin approval. Use scoped API keys to control access from your integrations. The API key guide explains how to create and revoke keys. Provider credentials have a separate setup guide.

Manage API keysConnect a model provider

What traces record

When enabled, trace capture records call metadata to help you inspect a run. Coverage depends on the execution path and configuration. A trace may not contain every event. Metadata-only capture does not mean that episode outputs, evaluator text or saved private inputs are not stored elsewhere.

Trace capture

Current procurement status

Documentation explains supported paths and limitations; it is not an independent certification or a guarantee for every deployment. Unknowns stay open until the responsible owner verifies them.

Where does the agent run and what is recorded?
Documented · Read the documentation and limits
What call metadata is captured and what are its limits?
Documented · Read the documentation and limits
How are API keys scoped and revoked?
Documented · Read the documentation and limits
How are customer model-provider credentials handled?
Documented · Read the documentation and limits
Hosting regions and encryption statements
Not yet verified · Pending approved provider inputs
Subprocessor inventory
Not yet verified · Pending approved provider inputs
Artifact retention and backup deletion
Not yet verified · Pending retention and deletion review
Approved security contact
Not yet verified · Pending named contact
Contractual service levels and certification evidence
Not yet verified · Pending contract terms; no certification is claimed
SAML or OIDC single sign-on
Not offered · Google, GitHub, and invite links are the supported sign-in paths

Company-managed provider keys and allowlists are unavailable. Individual BYOK is separate. Private challenge libraries do not establish a private VPC or on-premises deployment. DPA and MSA requirements are reviewed during scoping; no approved agreement or certification is implied.

Questions from your security team?

Include your requirements for hosting regions, subprocessors, data retention, or service terms when you request a security review.

Request a security review