Security and Trust at WALT
How we protect your data across ingestion, reasoning, and governance - with the controls, certifications, and transparency your team expects.
See section
Compliance

Framework
SOC 2

Framework
HIPAA
Subprocessors

GCP
Cloud Hosting Services Data location: United States
Monitoring
Continuously monitored by Secureframe
FAQs
How is Walt different from "an LLM that queries our data"?
aWalt uses deterministic data access through a controlled reasoning layer, not arbitrary model-generated queries against your systems.
Deterministic access: Data is retrieved through defined, scoped pathways rather than whatever query a model decides to generate.
Controlled reasoning (ReasonBase): The reasoning layer governs how the agent operates, keeping behavior bounded and reviewable.
Full traceability: Each step leaves a record, so actions can be audited after the fact.
The practical takeaway for a security team: Walt is designed to be safer and more predictable than a typical "point an LLM at the database" approach.
Do you train AI models on our data?
No. Customer data is not used to train models. Where Walt uses third-party LLM providers, we use them under zero-retention terms, so prompts and outputs are not retained or used for training by the LLM provider.
In addition to this, customers can use their own keys (BYOK) to configure WALT.
Is my data isolated from other customers' data?
Yes. For WALT hosted setup, each customer environment is logically isolated with scoped credentials, so an agent operating for one customer can only reach that customer's data.
Per-customer credentials and isolation are a core part of Walt's design. Access is scoped to the customer boundary by default, not enforced as an afterthought.