← Back to Overnight Compliance & audits

Your auditor’s first question, already answered.

A model wrote it, nobody reviewed it, and it is already running on production data. When the auditor asks what ran and who approved it, there is no answer. Overnight makes that answer a matter of record.

the archive — every run and every approval, written as it happens
Deny by defaultPer-tenant isolationSigned before it runsExportable audit trailSubprocessor of record
01 what the runtime guarantees

The answer is written as it happens.

Every call an app makes is recorded against an identity while it runs, refusals included. Nothing is reconstructed later from logs that were never designed to be evidence.

A compliant runtime is an execution environment where AI- and agent-written software runs with isolation, a complete audit trail, and policy enforcement applied by default, before the code touches real data. The controls are structural and always on, so what happened inside is something you can prove to an auditor.

When the request arrives, from an auditor, a customer, or your own security team, the work is an export you can run in an afternoon.

acme · manage / audit trail recording
apprefund-desk identityj.okafor · support events0
time call against decision
09:41:02 customers.read customer 8842 allow
09:41:02 orders.read order A-40913 allow
09:41:03 refunds.write order A-40913 · $40.00 allow
09:41:03 smtp.send not on the manifest denied
09:41:04 audit.write sealed · signed by tenant key allow
✕ denied The app asked to email the customer. Nobody granted that, so the boundary refused it — and the refusal is in the record too.
export evidence SOC 2 HIPAA GDPR one export answers the question your auditor opens with
what ran, who ran it, and what it was refused
  1. 01 the audit trail

    What ran, under whose identity, against which signed build

    If an auditor asked tomorrow what an AI-built app did to your data last quarter, most teams would be assembling the answer out of server logs that were never meant to be evidence. Overnight writes it down while it happens: the app, the identity behind it, the signed build, the data it touched, and the person who approved it.

    Refusals go into the same record, which is often the half that matters. A question about one customer over one date range becomes something you can answer the same afternoon, and it gives the same answer in year three as it does today.

  2. 02 layered enforcement

    Isolation at the hardware, network, and operating-system layers

    Every control here holds whether or not the generated code cooperates. Your tenant runs on its own virtualized boundary, separation is enforced beneath the operating system, and there is no default route out. Secrets, files, and system calls are brokered, so an app receives a result while the key stays somewhere it cannot see.

    That is also what settles the question most platform engineers ask second. The SDK catches mistakes on a laptop, but it was never the thing holding the line, and code that ignored it entirely still has nowhere to go and nothing to authenticate with.

  3. 03 per-tenant isolation

    Every customer gets a dedicated tenant of their own

    Your data sits behind walls of its own. The separation is structural, enforced underneath the code, which matters precisely because a model wrote that code. A dropped tenant check has nothing to reach.

    Host it with us, run it self-hosted in your VPC, or keep it on-premise and air-gapped. Where it sits is your call, and the controls do not change with it.

  4. 04 inherited controls

    The boundary carries the controls for every app inside it

    Isolation, identity, logging, retention, and egress policy belong to the runtime. Your apps do not implement them and cannot opt out of them, which is how one security review comes to cover the fiftieth app as well as the first.

    Overnight is built to the controls SOC 2, HIPAA, and GDPR ask about. The runtime enforces them once, so nobody assembles them again for every new workload. Where any certification stands today is something we will tell you directly, in writing.

    Ask us where we stand
  5. 05 past the sandbox

    Where a sandbox stops being enough

    A sandbox answers whether code can run without touching the host, and it is the right tool while an agent iterates. The question changes the moment that software points at real customer data, because now you have to show what it did and who approved it, weeks after the fact.

    That needs a tenant which persists, a record that outlives any single execution, and someone willing to sign your data-processing agreement. Most mature teams run both: a sandbox in the build loop, Overnight at the production boundary.

    The clean line between them
  6. 06 what it costs you

    One mediated hop, and your code stays yours

    Overhead lands on calls that cross the boundary, where a policy decision has to happen anyway. Work an app does inside its own process runs untouched, so for the internal tools, reports, and data jobs teams build here, the mediated hop is rarely what determines how long anything takes.

    Your apps are your own code, written against capabilities you granted, and they leave with you whenever you want. The audit trail exports too, because a record you cannot take with you is worth little to an auditor in year three.

  7. 07 subprocessor of record

    One name on your data-processing agreement

    Someone has to be accountable for what runs on your data, and the tool that generated it will not be, because its responsibility ended the moment the code existed. Overnight signs on as your runtime subprocessor of record.

    We own what executes, so we can put our name on your data-processing agreement. That gives the question which stalls most security reviews an actual party to point at.

· request access
Let’s build it

Make your next audit boring.

Approve the boundary once. Every app that runs inside it inherits a posture you can defend in the room.

Early access

Request access

Tell us where you want to run AI-written code and we will get back to you.

We use this to connect with you, and for nothing else. No recurring marketing emails.