Security design starts before the first prompt. Agents run inside your VPC or private cluster when contracts demand it. Secrets never leave your vault. Short lived tokens rotate with the rest of the firm platform. Network egress lists decide which tools can call out. Audit streams write every action with actor, timestamp, tool, and outcome so later review is cheap.
Prompt injection and tool abuse sit at the first defensive layer. Input filters, output scanners, and allow-listed tools exist by default. Dual control remains for money moves, identity changes, or legal sends. Those defaults come from years of locked down form workflows and self-hosted portals where inventory and status mistakes were expensive.
Compliance mapping covers SOC2 evidence packs, federal records rules, and HIPAA style isolation when health data appears. Retention windows apply to logs, prompts, and temporary memory alike. Legal and GRC join the second planning session rather than week six. Dulles corridor contractors nearly always need that early pass. We produce an evidence folder that closes findings without heroics at audit time.
Incident response manuals freeze the agent, redirect volume, and expand fixtures from the failure. Four hour recovery targets apply when writes are blocked. Penetration tests or red team prompts can run before cutover if your security org requires them. We never treat security as a phase that starts after demos. It is present at discovery and checked at every gate.