Decision Execution Governance
Security built for controlled AI agent rollout
On supported integrations and configured surfaces, dexgate evaluates covered actions before execution, keeps decision records for review, and manages policy changes in a controlled way.
Built for organizations that need clear deployment boundaries, controlled updates, reviewable evidence, and a defined AI-agent control layer.
Decision Execution Governance is the broader security model. Agent Execution Governance applies it to covered AI-agent actions on supported integrations before execution—not every host capability in every mode.
This page explains how Automated Decision Systems handles deployment boundaries, decision records, policy updates, and security reporting.
What this page covers
Data handling
dexgate keeps decision records focused on governance outcomes.
- Decision records capture the requested action, the policy applied, and the returned decision.
- Evidence is structured for security, audit, and engineering review.
- Deployments align data handling with customer environment and policy requirements.
Technical details
Reason codes and trace identifiers are available for governed review workflows. On the paid runtime, policy packs are verified with Ed25519 at load, and decision/passport evidence can be Ed25519-signed when outcome signing is enabled in the licensed secrets package. Free adapters use local hard gates only; OpenClaw adapter integrity files are local checksums, not the same as runtime decision signing.
Deployment boundaries
dexgate fits customer-controlled deployment boundaries.
- Supports customer-network deployment patterns.
- Supports different governance stages across development, test, and production environments.
Deployment details are documented during evaluation and rollout.
Controlled policy updates
Policy changes stay versioned, traceable, and reviewable.
- Policy updates are versioned and traceable.
- Decision evidence includes the policy version used at the time of evaluation.
What security teams review
Security, audit, and operational teams review the same governed evidence set.
How this fits your security stack
dexgate works with identity, sandboxing, and monitoring controls.
- Identity controls who can access systems.
- Sandboxing controls where code runs.
- Monitoring helps teams investigate what happened.
- Agent Execution Governance evaluates sensitive agent actions before they run.
Report a vulnerability
Include reproduction steps, observed behavior, and impact scope. We prefer coordinated disclosure: give us a reasonable chance to investigate and fix before public release of exploit details.
Security contact: security@dexgate.ai
Machine-readable policy: /.well-known/security.txt
Initial response target: 1 business day
Response target is an operational goal, not a contractual SLA unless stated in a signed agreement. Do not send secrets, customer data, or production credentials in initial reports—use a minimal reproduction when possible.
Important legal notice
Security, integrity, and signing statements on this page describe the product model and declared validation scope. They are not warranties that every deployment will prevent every incident or satisfy every legal or regulatory requirement.