Change language

Security

Security in Converged starts with transparency and control. The entire Converged codebase is open source under AGPL-3.0. There are no hidden proprietary components that users have to trust blindly. The code can be inspected, audited, modified, and deployed independently.

Converged uses AI-assisted security validation throughout the development and publication process. Code is automatically checked by AI models for vulnerabilities, unsafe patterns, architectural violations, and compliance with platform security rules before modules are accepted into the ecosystem. This creates a continuous security gate rather than relying only on manual review.

Data is isolated by workspace, tenant, and access boundary. Orders, customer files, production data, payments, messages, equipment data, and other business information remain separated according to the structure and permissions of the installation. Access is enforced for both human users and AI agents: an AI agent can only access data and perform operations allowed by its own permission profile, and actions are recorded for audit.

Enterprise provides the highest level of control. Converged is deployed directly into your infrastructure and your cloud accounts, using your own API keys and credentials. Your data, storage, network, secrets, backups, and AI resources remain inside your own control perimeter. 4IR does not require you to move your business data into a separate shared environment.

This model gives companies a choice between convenience and control without giving up ownership of their technology or data. The platform remains open source, the data remains portable, and Enterprise customers can operate Converged entirely within their own infrastructure and security policies.