Trust & Security
We don't claim security. Here's our live posture.
Andru is trust infrastructure, so our own security posture is part of the product. We run continuous, distributed monitoring across every surface of the platform. The numbers below are computed from live signals — not a once-a-year audit badge.
Continuous monitoring activelast sensor report Sep 20, 2026, 12:01 PM
Coverage
Surfaces monitored
3
backend, frontend, npm package
Detection rules
22
Rule categories
9
Detection & response (trailing 90 days)
Detections handled
118
Auto-contained
100%
automated containment on detection
Critical / High (30d)
14
Supply-chain integrity
Published artifacts are scanned by
andru-security-sensor.Continuous SCA/SAST/DAST scanning on every publish. Ed25519 signing, a public JWKS, and a hosted verifier are live; per-artifact WARDEN attestation activates on the next publish. npm provenance (SLSA, built-by-CI) is already in place.
Verifiable deliverables
Portfolio-readiness rollups, agent-to-agent results, and MCP tool outputs are cryptographically signed (Ed25519 / detached JWS).
Your team can verify it independently, offline, against our published public key (
/.well-known/jwks.json) — no need to trust our servers. We sign the answer, not just the connection.Remediation: Human-approved PR workflow — fixes are proposed automatically and merged by a human.
Posture computed Sep 20, 2026, 3:16 PM. Conducting technical diligence? Request the full security evidence kit.