Every Pokee workload runs inside a dedicated, isolated sandbox. Your data, your tokens, your traffic — controlled at every boundary.
Explore the threat landscape, an eight-module hardened architecture, and measured Pokee-Isaac results across 6,651 DecodingTrust-Agent tasks.
Dedicated subdomain, scoped auth, and a private session pool. No shared compute, no cross-tenant API surface.
TLS 1.2+ in transit, AES-256 at rest. Third-party tokens stored encrypted in a vault the agent cannot read.
Run Pokee in our cloud or your own VPC. See deployments →
Pokee has completed SOC 2 Type 2 and is undergoing ISO/IEC 27001 and ISO/IEC 42001 certification audits. Reports, policies, and our real-time control posture are published in the Pokee Trust Center.
Trust CenterPokee has completed its SOC 2 Type 2 examination across Security, Availability, and Confidentiality.
The SOC 2 Type 2 report is available through the Pokee Trust Center.
Pokee is undergoing certification audits for ISO/IEC 27001 information security management and ISO/IEC 42001 AI management systems.
Audit progress and certification materials will be published through the Trust Center.
Pokee engages an independent firm to conduct penetration tests against its production infrastructure. Findings are remediated and re-tested before reports publish.
Latest pen-test report available on request via the Trust Center.
Each layer is enforced independently — a failure of one does not collapse the others.
TLS 1.2+ on every public connection.
Compute and storage pinned to your chosen region.
Dedicated subdomain. No cross-tenant call surface.
Each session in its own OS mount namespace.
Per-session file scope, enforced by the OS.
Available on every enterprise tenant.
your-tenant.enterprise.pokee.ai — yours alone.
Mutual TLS available as defense against bearer leakage.
Restrict source IPs at the edge.
Route traffic through a hostname you control.
US, APAC, and EU regions on request.
No traffic crosses the public internet.
A locked-down variant of the API. The agent runs inside a sandbox whose only outbound network path is the model completion API — nothing else egresses.
No data exfiltration via the agent. Even prompt injection can't reach an attacker URL — the network drops it.
Hostname-allowlisted egress. All outbound traffic flows through one auditable proxy.
Same REST contract. Code written against the standard tenant works against an offline tenant.
Customer prompts, files, and outputs are not used to train Pokee models. Zero-data-retention routing on inference upstreams is enabled by default for enterprise tenants. Retention windows and deletion are contract-controlled.
We value the security research community. If you've found a vulnerability in Pokee, please report it confidentially.