Security

Security and governance for the agentic enterprise.

The trusted foundation to deploy, manage, and scale AI agents across your business. Every action is authenticated, authorized, and auditable by design.

Enterprise trust

Every request is known, controlled, and trusted.

Security at Msharti is not a bolt-on. It is the architecture. Identity, access policy, execution protection, and audit work together on every single call.

Verified identity

Every request carries the authenticated user identity. Agents act as known users, not anonymous services.

OAuth 2.1 / OIDCSAML SSOAPI key scopingTenant isolation

Governed access

RBAC, policy rules, and approval workflows decide which agents can call which tools and what they can do.

Role-based accessTool-level permissionsHuman-in-the-loopPolicy enforcement

Protected execution

Credentials never leave secure connector containers. Responses are stripped of secrets before they reach the AI.

AES-256-GCM at restTLS 1.3 in transitMemory-only decryptionSecret stripping

Audit everything

Every tool call is logged with identity, tool, tenant, timestamp, and outcome. Immutable and exportable.

Immutable logsSIEM streamingRetention tiersCompliance-ready exports
Built-in protections

Controls that matter for production AI.

From credential handling to attack prevention, Msharti includes the protections enterprises need before agents touch live systems.

Zero-trust architecture

No implicit trust. Every request is verified end to end.

Prompt-injection detection

Known attack patterns are blocked before they reach connectors.

SQL write-blocking

Database connectors are read-only by design. No accidental writes.

Adaptive rate limiting

Per-account limits keep agents from overwhelming your systems.

Data residency

Tenant data stays in Africa. Self-hosted options available.

Compliance alignment

Built for KPDPA, SOC 2, ISO 27001, and enterprise procurement.

Compliance

Aligned to the standards you are judged by.

Msharti is built to satisfy enterprise procurement, legal, and security review processes from day one.

KPDPA

Kenya Data Protection Act controls for personal data processing.

SOC 2

Controls for security, availability, and confidentiality.

ISO 27001

Information security management framework.

PCI DSS

Payment card data handling controls.

Ready for review

Get the security deep dive.

Talk to our team about architecture, compliance, deployment options, and how Msharti fits your security posture.