Current product + planned controls

Security

Trust starts with explicit state, traceable decisions, and accurate claims.

Steerlane's current product includes governance controls around approved state, reviewer identity, audit events, and reapproval decisions. Broader enterprise security capabilities are listed separately where they are still planned.

Security posture principle

We would rather show a capability as planned than imply a security control that does not yet exist.

Current product controls

What exists in the product today.

These are product-state and governance controls supported by the current implementation. They should not be interpreted as a completed enterprise security program.

Implemented
01

Explicit approval state

Production decisions are represented as explicit approval state rather than inferred from application behavior.

Pending and decided approval states
Decision state validation
Reviewer identity on decided approvals
Controlled approval transitions
02

Approved baseline snapshots

An approved baseline binds the accepted workflow state to the assurance state that supported the decision.

Workflow snapshot
Assurance snapshot
Approved baseline record
Version-linked governance state
03

Audit events

Governance actions can be recorded as explicit audit events with actor and target context.

Event type
Actor identity
Target identity
Timestamped event history
04

Human review identity

Where human review is required, reviewer identity and review state remain explicit rather than disappearing into an automated decision.

Reviewer ID
Reviewer name
Human-review tasks
Review outcomes
05

Reapproval blockers

Candidate workflows can remain ineligible for reapproval when required assurance or review conditions have not been satisfied.

Approval eligibility
Blocking reasons
Human-review requirements
Explicit unresolved state
06

Actor-aware evaluation actions

Candidate evaluation actions can carry actor identity into the audit trail rather than existing as anonymous state changes.

Actor ID
Evaluation input history
Audit event linkage
Traceable governance actions

Architecture principles

How we want the control layer to fit into enterprise environments.

These principles describe the architecture direction. They are not certifications or promises that every deployment option is already implemented.

01

Minimize unnecessary customer data movement

The product architecture should prefer references, structured evidence, and scoped workflow state over copying more customer data than is necessary for assurance decisions.

02

Keep customer infrastructure boundaries explicit

The long-term deployment model should support clear separation between Steerlane's control layer and the customer's models, tools, data systems, and execution environment.

03

Preserve evidence ownership

Evidence should remain attributable to its source and reusable without requiring Steerlane to become the system of record for every underlying artifact.

04

Separate environments and governance state

Development, testing, and production approval states should remain distinguishable so experimental changes are not confused with approved production state.

Planned enterprise controls

Important controls that are not presented as generally available today.

These are expected enterprise requirements, but they remain planned until the relevant implementation and operational evidence exists.

Important

Steerlane does not currently claim SOC 2 certification, SSO / SAML availability, configurable data residency, BYOC, or enterprise key-management capability.

SSO / SAMLPlanned
Enhanced enterprise RBACPlanned
SOC 2 readiness and certification workPlanned
Configurable data residencyPlanned
BYOC / customer-hosted execution optionsPlanned
Enterprise key-management integrationsPlanned

Claim boundary

What this page does not imply.

Current governance controls should not be confused with a completed enterprise security stack.

No certification claim

SOC 2 is not claimed today.

Certification requires independent controls, operating evidence, and formal audit work beyond the current product implementation.

No identity-platform claim

SSO and enterprise RBAC are not claimed today.

Reviewer and actor identity exists in governance state, but that is not the same as a production enterprise identity and access-management layer.

No hosting-boundary claim

BYOC and data residency remain planned.

The architecture direction supports explicit deployment boundaries, but those deployment modes are not presented as generally available today.

No silent automation claim

Human review remains part of the control model.

Where assurance or reapproval requires human judgment, the product keeps reviewer identity and review state explicit.

Design-partner evaluation

Review product controls and deployment requirements before a pilot.

A design-partner pilot should include an explicit discussion of workflow boundaries, evidence handling, reviewer roles, and enterprise security requirements.