Proof, not promises.
Argos OS is built by a cybersecurity company. Security isn't a feature bolted on at the end — it's the architecture. Here is exactly how we protect your data and prove our integrity.
A crown-jewel kernel
The Argos Kernel — which holds identity and the client graph — runs internal-only with no public ingress, its own database, and constant-time service-token authentication. The most sensitive component is the least exposed.
Hash-chained, Bitcoin-anchored audit
Critical events are written to an append-only, hash-chained log and anchored to the Bitcoin blockchain via OpenTimestamps. Tampering is mathematically detectable — independently verifiable proof of who did what, when. Authorship and content gain true non-repudiation: provable, not merely logged.
Private AI — zero data retention
The private AI gateway lets your CISO set which model tier each workload may use, per tenant, and enforces it centrally. Prompts are never stored — only SHA-256 hashes are logged for audit.
Hardened against our own red team
Every product is reviewed and attacked internally before release — rate-limiting, IDOR client-scoping, SSRF guards, least-privilege scoped service keys, and secret rotation with history purge. We dogfood it on our own MSP fleet first.
Encryption everywhere
Data is encrypted in transit (TLS) and at rest. Traffic is fronted by a global edge with WAF, rate-limiting and DDoS protection, and origins are isolated behind authenticated tunnels.
Compliance built in
Argos GRC continuously maps live evidence across CIS v8.1, NIST CSF 2.0, SOC 2, HIPAA, ISO 27001, PCI DSS 4.0, NY DFS 500, NIST 800-171, CMMC L1/L2, CJIS and more — so your own posture is always audit-ready.
Provable trust, anchored to the blockchain.
Most platforms ask you to trust their audit logs. Argos makes that trust mathematical. Every signature, approval and critical action is written to an append-only, hash-chained record and anchored to the Bitcoin blockchain through OpenTimestamps — so what happened, who did it, when, and to which exact bytes can be proven by anyone, independent of us.
- Authorship & content, sealed. A PAdES-LTA digital signature over a tamper-evident hash chain. Alter a single byte and the proof breaks — the record defends itself.
- Verified identity, cryptographically bound. Argos Verify’s phish-resistant, transaction-bound MFA establishes who approved — and that approval is bound to the exact content and timestamp inside the evidence record. Argos Identity governs the accounts behind it.
- Independently verifiable, forever. A Bitcoin anchor via OpenTimestamps proves the record existed, unaltered, as of a point in time — trustless and checkable against the public chain, even if Argos is offline.
Three independent proofs. No “trust us” required.
Your identity provider. Your rules. Argos adapts.
Argos OS doesn’t force a new identity stack on you. Federate the platform to the directory you already standardized on — Microsoft Entra ID, Google Workspace, or JumpCloud — and your team signs in with credentials they already have. Argos never sees or stores their password; it receives only a verified assertion, then issues its own scoped, fully-audited session.
- No premium license tax. Sign-in works with Entra ID Free. P1/P2 only matter if you want your own Conditional Access, group-based assignment, or automated provisioning — and if you have them, Argos inherits them.
- Govern access from one place. Argos access is anchored to your directory — cut off a user’s sign-in upstream and they can no longer authenticate into Argos. One identity to manage, not many.
- Isolation is absolute. Each tenant attaches its own identity provider, independently. Your directory authenticates only your tenant — never another customer’s data.
- Every sign-in, sealed. Logins and role grants land in the same hash-chained, Bitcoin-anchored audit log — provable, not merely recorded.
Your login. Any tier. Zero lock-in.
Found a vulnerability?
We welcome good-faith security research. If you believe you've found a vulnerability in Argos OS or argos-os.com, please email [email protected] with details and reproduction steps. Please do not access or modify data that isn't yours, and give us a reasonable window to remediate before public disclosure. We'll acknowledge your report and keep you updated.
Security questions? We have answers.
Request our security overview, a SOC 2 status update, or a live architecture walkthrough.