← Back to OvernightCompliance & audits

Your auditor’s first question, already answered.

A model wrote it, nobody reviewed it, and it is already running on production data. When the auditor asks what ran and who approved it, there is no answer. Overnight makes that answer a matter of record.

the archive — every run and every approval, written as it happens
Deny by defaultPer-tenant isolationSigned before it runsExportable audit trailSubprocessor of record
01 what the runtime guarantees

The answer is written as it happens.

Every call an app makes is recorded against an identity while it runs, refusals included. Nothing is reconstructed later from logs that were never designed to be evidence.

A compliant runtime is an execution environment where AI- and agent-written software runs with isolation, a complete audit trail, and policy enforcement applied by default, before the code touches real data. The controls are structural and always on, so what happened inside is something you can prove to an auditor.

When the request arrives, from an auditor, a customer, or your own security team, the work is an export you can run in an afternoon.

acme · manage / audit trailrecording
apprefund-deskidentityj.okafor · supportevents0
timecallagainstdecision
09:41:02customers.readcustomer 8842allow
09:41:02orders.readorder A-40913allow
09:41:03refunds.writeorder A-40913 · $40.00allow
09:41:03smtp.sendnot on the manifestdenied
09:41:04audit.writesealed · signed by tenant keyallow
✕ deniedThe app asked to email the customer. Nobody granted that, so the boundary refused it — and the refusal is in the record too.
export evidenceSOC 2HIPAAGDPRone export answers the question your auditor opens with
what ran, who ran it, and what it was refused
  1. 01the audit trail

    What ran, under whose identity, against which signed build

    If an auditor asked tomorrow what an AI-built app did to your data last quarter, most teams would be assembling the answer out of server logs that were never meant to be evidence. Overnight writes it down while it happens: the app, the identity behind it, the signed build, the data it touched, and the person who approved it.

    Refusals go into the same record, which is often the half that matters. A question about one customer over one date range becomes something you can answer the same afternoon, and it gives the same answer in year three as it does today.

  2. 02layered enforcement

    Isolation enforced beneath the workload, not opt-in for it

    Every control here holds whether or not the generated code cooperates. Each workload runs inside its own sandboxed boundary, with separation enforced beneath the operating system the app can see, and there is no default route out. Secrets, files, and system calls are brokered, so an app receives a result while the key stays somewhere it cannot see.

    That is also what settles the question most platform engineers ask second. The SDK catches mistakes on a laptop, but it was never the thing holding the line, and code that ignored it entirely still has nowhere to go and nothing to authenticate with.

  3. 03per-tenant isolation

    Every customer gets a dedicated tenant of their own

    Your data sits behind walls of its own: your own database, your own sandboxed workload boundary. That separation is structural, enforced underneath the code, which matters precisely because a model wrote that code. A dropped tenant check has nothing to reach.

    The network edge in front of that boundary is shared infrastructure across every customer today. We disclose that rather than leave it for you to find, because the isolation claim above is about your data and your workload, not every component in front of it.

  4. 04inherited controls

    The boundary carries the controls for every app inside it

    Isolation, identity, logging, retention, and egress policy belong to the runtime. Your apps do not implement them and cannot opt out of them, which is how one security review comes to cover the fiftieth app as well as the first.

    Overnight is built to the controls SOC 2, HIPAA, and GDPR ask about. The runtime enforces them once, so nobody assembles them again for every new workload. Where any certification stands today is something we will tell you directly, in writing.

    Ask us where we stand →
  5. 05past the sandbox

    Where a sandbox stops being enough

    A sandbox answers whether code can run without touching the host, and it is the right tool while an agent iterates. The question changes the moment that software points at real customer data, because now you have to show what it did and who approved it, weeks after the fact.

    That needs a tenant which persists, a record that outlives any single execution, and someone willing to sign your data-processing agreement. Most mature teams run both: a sandbox in the build loop, Overnight at the production boundary.

    The clean line between them →
  6. 06what it costs you

    One mediated hop, and your code stays yours

    Overhead lands on calls that cross the boundary, where a policy decision has to happen anyway. Work an app does inside its own process runs untouched, so for the internal tools, reports, and data jobs teams build here, the mediated hop is rarely what determines how long anything takes.

    Your apps are your own code, written against capabilities you granted, and they leave with you whenever you want. The audit trail exports too, because a record you cannot take with you is worth little to an auditor in year three.

  7. 07subprocessor of record

    One name on your data-processing agreement

    Someone has to be accountable for what runs on your data, and the tool that generated it will not be, because its responsibility ended the moment the code existed. Overnight signs on as your runtime subprocessor of record.

    We own what executes, so we can put our name on your data-processing agreement. That gives the question which stalls most security reviews an actual party to point at.

· request access
Let’s build it

Make your next audit boring.

Approve the boundary once. Every app that runs inside it inherits a posture you can defend in the room.

Early access

Request access

Tell us where you want to run AI-written code and we will get back to you.

We use this to connect with you, and for nothing else. No recurring marketing emails.