Integration infrastructure with security built into every layer.

Paragon powers product integrations and agent workflows for regulated enterprises. The platform is SOC 2 Type II, HIPAA, and GDPR compliant, and can run entirely in your cloud.

Trusted by enterprise platforms and AI products to handle integrations at scale.

Trusted by enterprise platforms and AI products to handle integrations at scale.

Independently audited and compliant.

Independently audited and compliant.

Our SOC 2 Type II controls are independently audited on a recurring cycle. The report, DPA, and supporting security documentation are available in the Trust Center.

Our SOC 2 Type II controls are independently audited on a recurring cycle. The report, DPA, and supporting security documentation are available in the Trust Center.

SOC 2 TYPE II

GDPR compliant

HIPAA compliant

VPC compatible

ISO 27001

Coming soon

ISO 27001

Coming soon

Run Paragon in your cloud, or ours.

The platform is the same however you run it. You decide how much runs inside your perimeter.

Multi-tenant cloud (US or EU)

Our managed SOC 2 Type II cloud, with US or EU data residency and the fastest path to production.

Self-hosted in your VPC

Deploy Paragon to your own AWS, GCP, or Azure account, managed by Paragon or fully by your team. Your customers' data and integration traffic never leave your environment.

Forward-deployed

Embed Paragon in your product and deploy it in your customer's environment.

How your data is protected.

How your data is protected.

Encrypted at-rest and in-transit, isolated per customer, and kept inside your environment when you self-host.

Encrypted at-rest and in-transit, isolated per customer, and kept inside your environment when you self-host.

Encrypted credential vault

Third-party credentials sit in a separate vault, each under its own key. Keys and encrypted values are stored apart, so neither is usable without the other.

Encrypted credential vault

Third-party credentials sit in a separate vault, each under its own key. Keys and encrypted values are stored apart, so neither is usable without the other.

Encrypted credential vault

Third-party credentials sit in a separate vault, each under its own key. Keys and encrypted values are stored apart, so neither is usable without the other.

AES-256 and TLS 1.2+

Encrypted with AES-256 at rest and TLS 1.2+ in transit.

AES-256 and TLS 1.2+

Encrypted with AES-256 at rest and TLS 1.2+ in transit.

AES-256 and TLS 1.2+

Encrypted with AES-256 at rest and TLS 1.2+ in transit.

Kept out of logs

Event logs are stored separately with sensitive values redacted; emails and passwords are never logged.

Kept out of logs

Event logs are stored separately with sensitive values redacted; emails and passwords are never logged.

Kept out of logs

Event logs are stored separately with sensitive values redacted; emails and passwords are never logged.

Isolation you control

On managed installs, support access is temporary, approved, and logged, and credentials stay inaccessible even to us. For self-hosted instances, your data never leaves the installation.

Isolation you control

On managed installs, support access is temporary, approved, and logged, and credentials stay inaccessible even to us. For self-hosted instances, your data never leaves the installation.

Isolation you control

On managed installs, support access is temporary, approved, and logged, and credentials stay inaccessible even to us. For self-hosted instances, your data never leaves the installation.

Minimal or zero outbound data

Self-hosted deployments minimize outbound data, limiting requests to a license check, usage metadata, and anonymized analytics. Air-gapped deployments can be supported as well, so nothing ever leaves.

Minimal or zero outbound data

Self-hosted deployments minimize outbound data, limiting requests to a license check, usage metadata, and anonymized analytics. Air-gapped deployments can be supported as well, so nothing ever leaves.

Minimal or zero outbound data

Self-hosted deployments minimize outbound data, limiting requests to a license check, usage metadata, and anonymized analytics. Air-gapped deployments can be supported as well, so nothing ever leaves.

High availability and recovery

In our managed cloud, Paragon spans multiple AWS availability zones with replication, tolerating the loss of a single zone. Encrypted backups with point-in-time recovery restore data to a chosen moment.

High availability and recovery

In our managed cloud, Paragon spans multiple AWS availability zones with replication, tolerating the loss of a single zone. Encrypted backups with point-in-time recovery restore data to a chosen moment.

High availability and recovery

In our managed cloud, Paragon spans multiple AWS availability zones with replication, tolerating the loss of a single zone. Encrypted backups with point-in-time recovery restore data to a chosen moment.

Controlled access. Complete audit trails.

Controlled access. Complete audit trails.

Human and agent actions pass through role-based access and into a searchable audit trail, available on demand.

Human and agent actions pass through role-based access and into a searchable audit trail, available on demand.

Access & identity

Role-based access control enforces least privilege. SAML single sign-on for enterprise, and multi-factor authentication on cloud and self-hosted deployments.

Access & identity

Role-based access control enforces least privilege. SAML single sign-on for enterprise, and multi-factor authentication on cloud and self-hosted deployments.

Access & identity

Role-based access control enforces least privilege. SAML single sign-on for enterprise, and multi-factor authentication on cloud and self-hosted deployments.

Locked to your systems

Every customer is isolated by default in our multi-tenant cloud. Allowlist Paragon's published egress IPs so your systems accept integration traffic only from Paragon, and reject everything else.

Locked to your systems

Every customer is isolated by default in our multi-tenant cloud. Allowlist Paragon's published egress IPs so your systems accept integration traffic only from Paragon, and reject everything else.

Locked to your systems

Every customer is isolated by default in our multi-tenant cloud. Allowlist Paragon's published egress IPs so your systems accept integration traffic only from Paragon, and reject everything else.

Event history

Integrations, syncs, and agent actions are recorded in Event Logs across Managed Sync, ActionKit, and Workflows. Each event carries a timestamp, type, trace ID, user ID, credential ID, and status.

Event history

Integrations, syncs, and agent actions are recorded in Event Logs across Managed Sync, ActionKit, and Workflows. Each event carries a timestamp, type, trace ID, user ID, credential ID, and status.

Event history

Integrations, syncs, and agent actions are recorded in Event Logs across Managed Sync, ActionKit, and Workflows. Each event carries a timestamp, type, trace ID, user ID, credential ID, and status.

Governance for agents that take action.

Your product's AI agents act autonomously across hundreds of systems. Paragon runs those actions through the same access, scoping, and audit controls as your human-triggered integrations, without opening a gap in control.

One pipeline for humans and agents

Agent and human actions share one control path, with guardrails built in by default.

One pipeline for humans and agents

Agent and human actions share one control path, with guardrails built in by default.

One pipeline for humans and agents

Agent and human actions share one control path, with guardrails built in by default.

Scoped to least privilege

Each agent gets only the systems and permissions it needs, granted per connection, so a single action can't reach beyond its scope.

Scoped to least privilege

Each agent gets only the systems and permissions it needs, granted per connection, so a single action can't reach beyond its scope.

Scoped to least privilege

Each agent gets only the systems and permissions it needs, granted per connection, so a single action can't reach beyond its scope.

Complete action log

A complete, searchable record of what each agent did, where, and with what result.


Complete action log

A complete, searchable record of what each agent did, where, and with what result.


Complete action log

A complete, searchable record of what each agent did, where, and with what result.


Built to carry production load.

Trusted by enterprise platforms and AI products

Requests per month

0B+
0B+

Uptime commitment (SLA), measured per fiscal quarter

50.0%
50.0%

Trusted by Enterprise platforms

How we operate securely, day to day.

Incident response

We treat all security incidents with a documented incident response plan, a rotating 24/7 on-call team and CTO-led recovery. Affected customers are notified within one business day, enterprise customers get a shared Slack channel, and each incident ends in a formal post-mortem.

Secure development

We run SAST, DAST, dependency, and container checks in CI, alongside continuous vulnerability scanning. Each production change is code-reviewed, logged, and approved before it ships.

Independent penetration testing

Independent firms run penetration tests twice a year; summaries are available under NDA.

Resilient infrastructure

All Paragon infrastructure is protected by a WAF and multiple layers of access control are provisioned to prevent access to any sensitive data in any unwarranted scenario.

“Security isn't a final layer. Audit, isolation, encryption, and revocation hold the same way in our cloud or entirely in your own. Security teams shouldn't have to trade control for convenience.”

“Security isn't a final layer. Audit, isolation, encryption, and revocation hold the same way in our cloud or entirely in your own. Security teams shouldn't have to trade control for convenience.”

Ishmael Samuel

CTO and CISO, Paragon

Your security review starts here.

Request our security package: the SOC 2 Type II report, DPA, and the details your team needs to sign off.

Trusted by enterprise platforms and AI products to handle integrations at scale.

FAQ

Have more questions? Book a call

Where does my data live, and can it stay in my own cloud?
How is my data encrypted?
Which certifications do you hold, and how do I get the reports?
How are agent actions controlled and logged?
What happens during a security incident?
How do you handle sub-processors and data deletion?