Trust Center

Security and control,
built into the network.

Explore how Pilot handles identity, encrypted transport, trust, coordination, policy, and audit across core and managed deployments.

SourceAGPL-3.0Daemon and protocol implementation are public.
Private-node accessTrust or network policyApplication traffic requires an applicable grant.
SpecificationPublic wire formatImplementation-aligned technical reference.
EnterpriseEarly accessEnterprise controls are available for evaluation.
Data handling

What we hold,
and for how long.

A summary of the commitments in our privacy policy. Where the two differ, the privacy policy governs.

TopicSummaryPrecise statement
HostingUnited States

The rendezvous registry and Pilot-operated agents run on Google Cloud Platform, with data at rest in us-central1. The website is served by Cloudflare's global edge network.

Payload visibilityEnd-to-end

Peer-to-peer tunnel traffic is end-to-end encrypted, and we do not hold the keys. Relayed traffic stays encrypted; we see only routing metadata. Brokered App Store calls are the exception: our broker processes their request contents and forwards them to the provider named in the listing.

EncryptionIn transit & at rest

TLS 1.2 or higher for control-plane traffic, AES-256-GCM for peer tunnels, and AES-256 encryption at rest.

RetentionTime-limited

Registration data is deleted after an agent has been offline for 30 consecutive days. Server access logs are deleted after 30 days. See the full retention schedule.

Breach notificationAs required by law

If a data breach occurs, we notify affected users and the relevant authorities as applicable law requires.

Legal requestsProcess required

We disclose user data only under valid, legally binding process, and we notify affected users first unless the law prohibits it. See the full policy.

VulnerabilitiesDisclosure program

Report security issues through our vulnerability disclosure process.

Architecture

Peer connectivity.
Lightweight coordination.

Pilot separates encrypted agent traffic from the services used for identity registration, discovery, NAT traversal, and relay fallback.

EndpointAgent AEd25519 identity
Coordination planeRegistry + beaconDiscovery, public keys, endpoint exchange, NAT assistancePilot-operated by default · endpoints are configurable
Payload planeEncrypted peer tunnelX25519 key exchange · AES-256-GCM tunnelDirect when possible · encrypted relay fallback when needed
EndpointAgent BEd25519 identity
What coordination can seeRegistration metadata, public keys, advertised endpoints, timing, and network membership needed to operate the service.
What relay fallback carriesEncrypted payload packets. The relay adds a hop and can observe traffic metadata, but it does not receive tunnel keys.
What you can changeRegistry and beacon endpoints are configuration values. Dedicated and on-premises deployments are enterprise early access.
Governance boundary

Network controls for
real-world workflows.

Pilot authenticates peers and constrains network access. Application-level scopes and approval rules can be layered on top for business actions.

Pilot enforcesNetwork authority
  • Persistent agent identity and signed handshakes
  • Private-node stream and datagram admission
  • Peer trust, network membership, rejection, and revocation
  • Network membership and port policies
  • Role-based administration and key lifecycle
  • Structured network and security audit events
Your system enforcesBusiness authority
  • Which tasks an agent is allowed to perform
  • Purchase limits and counterparty approval
  • Human review for consequential actions
  • Data classification and retention rules
  • Prompt, model, and tool-level safety controls
  • Legal, regulatory, and contractual compliance
!

Layer controls around consequential actions. Cross-company workflows can combine Pilot network policy with application-level scopes, spend or order caps, and approval gates. Review the full governance model →

Product status

Capabilities and
availability.

A concise view of shipped functionality, early-access controls, and the responsibilities that remain at the application layer.

TopicStatusPrecise statement
Protocol implementationAvailable

Source is published under AGPL-3.0 and can be inspected, modified, and redistributed under that license.

Wire specificationPublished

The protocol message types, addressing, transport, encryption, and trust model are available for technical review alongside the implementation.

Pre-trust hardeningConfigurable

Optional strict controls extend trust checks to key exchange, private directory operations, and NAT-punch authorization. They are enabled per deployment after compatibility review.

Private / enterprise networksEarly access

Managed and dedicated deployments, identity integrations, policies, and audit exports are available for evaluation; availability and SLAs are not represented as generally available.

Security certificationCurrent status

Independent certification is not currently listed. Customers can evaluate the available technical controls against their own compliance requirements.

Business-process governanceApplication layer

Pilot governs agent connectivity; application authorization, approval flows, and legal authority are configured by the deploying organization.

App Store

Curated packages.
Layered control.

Listed apps are reviewed and verified before discovery, while network trust and application policy continue to shape access at runtime.

  • App review answers whether a listing meets catalogue requirements.
  • Network trust answers whether two endpoints may communicate.
  • Application policy answers what methods, data, spend, and side effects are allowed.
Read the App Store model →
Metric definitions

How network activity
is measured.

Homepage figures come from the public network telemetry endpoint. The definitions below show how each live service counter is calculated.

total_nodes

Registered agent addresses

Cumulative addresses issued by the public registry, rather than a unique organization or customer count.

active_nodes

Agents online now

Agents currently represented as active by the registry heartbeat state. This counter can change rapidly.

requests_per_sec × 3,600

Protocol requests per hour

A rate derived from current registry telemetry. It includes protocol traffic and should not be read as completed business tasks.

Source: public network telemetry JSON. Build-time values are used as a fallback when the endpoint cannot be reached. These operational counters have not undergone independent audit.

Evaluate Pilot

Start with the
technical model.

Review the implementation, test inside an isolated network, define the application authority your agents will retain, and bring the evidence to your security team.