TrustSecurity architecture

Governance you can verify.

Savant is built so every skill can be traced to its source, every release to its evidence, and every change to a person who approved it.

Identity and access

  • Single sign-on through Auth0 by default, or your own identity provider over OIDC or SAML.
  • SCIM provisioning keeps members and groups aligned with your directory.
  • Role-based access control; approval tiers and reviewers are defined in policy.

Data handling

  • Your Git repository remains the source of truth for skill content.
  • Savant stores references to commits, evaluation results, release records, and audit events.
  • Workspaces are tenant-isolated; access is always scoped to one workspace.

Provenance and release control

  • Every skill version resolves to a commit, and every release to evaluated content.
  • Release records are signed; promotion runs draft → staging → production under policy.
  • Auto-pin on regression holds the prior version; rollback is one action.

Audit

  • Changes, approvals, releases, and access events are recorded append-only.
  • Audit events can be exported to your SIEM.

Bounded improvement

  • Run telemetry is redacted and pseudonymized before analysis; capture level follows your tenant setting.
  • The optimization worker holds no database, Git, or release credentials.
  • Locked sections of a skill cannot be read or changed by the optimizer.
  • Only authorized people approve a recommendation. There is no autonomous deployment mode.