Security and governance
Per-project rights (RBAC)
Section titled “Per-project rights (RBAC)”A project is the unit of rights, quotas and cost. Rights are given to users, to groups federated
from your directory and to service accounts, through assignments (see
roles and permissions). Roles and assignments are checked by
dedicated platform-side tests (RbacIT).
AI agents (MCP)
Section titled “AI agents (MCP)”The MCP server exposes read tools (list projects, jobs, the catalog, costs…) and write tools (upload code, create, run and schedule a job). No deletion tool is enabled by default. Each agent acts under a service account with limited rights, and every action is notified live in the console (the “Agents” feed).
The LLM that drives the agents remains your choice: tool results pass through it, which is a setting to tune based on the sensitivity of your data. MCP is an open standard, governed by the Agentic AI Foundation (Linux Foundation) since 09/12/2025.
A tenant’s secrets
Section titled “A tenant’s secrets”A tenant’s secrets (credentials of its buckets, client secret of a graal Application) are
encrypted in the database, with AES-256-GCM, using a key derived per tenant: HKDF-SHA256
(RFC 5869) applied to an installation root key, with the tenant identifier as context. The stored
value carries the enc:v1: prefix; the plaintext exists in memory only, for the duration of one
call, and is returned only to a caller with read permission on the secret.
The root key is an environment variable of the platform, supplied by your secrets manager. It is generated once, at installation, and backed up like a database encryption key: the secrets sealed with it only open with it (see installation).
The audit log ties every action to its actor, human or agent: who, what, on which resource, when. On top of it come the login history (Keycloak) and the run history. A job created by an agent also carries its own origin labels (see AI agents). The site’s Governance page presents the whole picture.
Qualified hosting providers
Section titled “Qualified hosting providers”SecNumCloud and HDS qualify cloud offerings and hosting providers, not software. graal is deployable with a SecNumCloud-qualified or HDS-certified hosting provider, or in your own datacentre. Disk encryption, denial-of-service protection and threat detection belong to your infrastructure and your hosting provider.
Reporting a vulnerability
Section titled “Reporting a vulnerability”Responsible disclosure policy: see
/.well-known/security.txt (RFC 9116).