Documentation map
Use this map to choose a starting page by task. The links are grouped by the work a reader or coding agent needs to do. For programmatic reading, append .md to the page path, as described on the documentation home.
Security facts to keep in view
- Local enforcement is topological through an internal-only network and gateway sidecar.
- Cloud default-tier enforcement is at the per-instance egress boundary through the control plane and gateway. It is not presented as substrate-enforced isolation.
- The paid, on-request high-assurance tier uses substrate-enforced network policy in a dedicated Kubernetes namespace.
- The governed network scope is HTTP and HTTPS. Raw TCP, UDP, and ICMP are outside the current transparent proxy model.
- AgentPaaS does not claim to prevent prompt injection.
- AgentPaaS is working toward SOC 2 and is not yet certified.
- AgentPaaS Cloud data is processed and stored in the United States.