Skip to main content

Documentation map

Use this map to choose a starting page by task. The links are grouped by the work a reader or coding agent needs to do. For programmatic reading, append .md to the page path, as described on the documentation home.

TaskStart hereFollow-up pages
Understand AgentPaaS and its deployment flowWhat is AgentPaaS?The 30-minute path, AgentPaaS concepts
Complete the trial happy pathThe 30-minute pathSet up AgentPaaS, LLM key guide, Troubleshooting
Install the local CLICLI installDaemon, Doctor, CLI overview
Build and test a local projectProjectsPack and run, Policy, Audit and lineage
Build an agentBuild an agentAgents, What is AgentPaaS?
Build an MCP serverBuild an MCP serverMCP servers, MCP demos
Build a toolBuild a toolTools
Compose a workflowWorkflowsWorkflow kinds and edges, Platform limits
Log in to CloudCloud loginCloud, Cloud pull
Push, deploy, invoke, or inspect a Cloud runCloudRuns, audit, and logs, Audit and lineage
Manage local or Cloud credentialsCredentials and secretsSecrets and bindings, Data handling
Define or inspect policyPolicyHow enforcement works, Known limitations
Understand the platform architectureArchitectureThreat model, How enforcement works
Compare enforcement tiersHow enforcement worksThreat model, Known limitations
Review security boundaries and claimsThreat modelKnown limitations, Architecture
Check current security gapsKnown limitationsThreat model, Audit export
Review governance and auditGovernance and auditRuns, audit, and logs, Audit export, Audit and lineage
Export and verify audit evidenceAudit exportGovernance and audit, Known limitations
Review compliance status and subprocessorsCompliance and attestationsThreat model, Data handling
Check data residency and provider handlingData handlingArchitecture, Compliance and attestations
Review package identity and provenanceTrust modelIdentity and trust, Known limitations
Find current product limitsPlatform limitsKnown limitations
Troubleshoot a trial or runTroubleshootingThe 30-minute path, Doctor
Read release changesRelease notes v0.4.0Documentation home

Security facts to keep in view

  • Local enforcement is topological through an internal-only network and gateway sidecar.
  • Cloud default-tier enforcement is at the per-instance egress boundary through the control plane and gateway. It is not presented as substrate-enforced isolation.
  • The paid, on-request high-assurance tier uses substrate-enforced network policy in a dedicated Kubernetes namespace.
  • The governed network scope is HTTP and HTTPS. Raw TCP, UDP, and ICMP are outside the current transparent proxy model.
  • AgentPaaS does not claim to prevent prompt injection.
  • AgentPaaS is working toward SOC 2 and is not yet certified.
  • AgentPaaS Cloud data is processed and stored in the United States.