Agents execute. A named human approves.
Autonomy is only worth buying if someone can say who authorised a given action, and prove it afterwards. This page is how PrescientIQ™ is governed — what is enforced in the architecture, whose certifications sit underneath it, and, in its own section, what we do not claim.
The short version: an agent does the work continuously, and every externally visible action stops and waits for a person. Not because the model cannot be trusted with the work, but because nobody should have to reconstruct, after the fact, who let a message reach a customer.
Control is architectural, not a setting
The distinction that matters in this category is whether a restriction is enforced or merely requested. An agent instructed to “always ask before sending” is a model being asked to behave, and a sufficiently unusual input can talk it out of that. An agent with no capability to send without an approval token is a constraint it cannot route around.
A named human approves every external action
An agent can research, score, and draft continuously. It cannot send an email, or write a field a customer-facing system would show, until a specific person approves that specific action. The gate is enforced at the tool layer — there is no code path around it, and no configuration that removes it.
Every agent holds its own scoped identity
Each agent runs under a per-agent, least-privilege identity rather than a shared service account or a borrowed human credential. That is what makes entitlements enumerable, actions attributable to a specific agent, and revocation possible without disabling a person.
Deterministic code for anything with a numeric consequence
Scores, rankings, and prioritisation thresholds are computed by sandboxed deterministic code, never by asking a language model to do arithmetic. The same inputs produce the same number every time, which is what makes a score reviewable instead of merely plausible.
Evidence you can audit, not a summary you have to trust
The question a review actually asks is not whether the model is good. It is: when this is wrong, who finds out, how fast, and what record exists afterwards.
Recorded as it happens, not reconstructed on request
Every action is written to an immutable ledger with the rationale behind it and the identity of the human who approved it, at the moment it occurs. The difference between that and a report generated when someone asks is the difference between evidence and an assertion.
Prompt-injection defense on every inbound surface
Agents read external content — web pages, email replies, CRM fields other people write into. Every one of those is an untrusted input, and each inbound surface is defended accordingly rather than assumed safe because it arrived through a familiar integration.
The architecture stated in full, in one place:
PrescientIQ is hosted and operated by MatrixLabX on Google Cloud, which maintains SOC 2, ISO 27001, and PCI DSS-attested infrastructure. Per-agent least-privilege identities, prompt-injection defense on every inbound surface, and an immutable audit ledger record every action, its rationale, and the approving human.
Whose certifications these actually are
Most trust pages in this category put a row of compliance badges near the top and let the reader assume they belong to the vendor. Usually they belong to the cloud provider underneath. Both facts matter, and they are different facts, so we separate them explicitly:
Held by Google Cloud
SOC 2, ISO 27001, and PCI DSS attestations are held by Google Cloud, which operates the underlying infrastructure. They are not MatrixLabX certifications.
Held by MatrixLabX
MatrixLabX application-layer SOC 2 is in progress.
Availability, stated as engineering rather than contract
Engineered availability SLO of ≥99.5% on the model and inference path, with named third-party carve-outs (Salesforce, HubSpot, intent-data vendors, email delivery).
What we do not claim
A trust page that only lists strengths is a marketing page wearing a different hat. These are the limits, stated here so you do not have to discover them in week three of an evaluation:
We are not SOC 2 certified at the application layer.
That work is in progress. The attestations associated with the infrastructure are Google Cloud’s, and we attribute them that way everywhere rather than arranging them into a badge row that reads as ours.
We do not publish measured customer outcome figures.
We are at founding-pilot stage. Percentage improvements you see attached to this category are usually modeled projections; where we show any figure at all, it carries its proof class and its qualifier with it.
We do not offer a contractual uptime SLA.
We publish an engineered availability SLO instead, with third-party dependencies named and carved out — because an availability number larger than the SLAs of the services underneath it is not a commitment that survives contact with an incident.
We do not answer deep data-handling questions on a marketing page.
Model-training exclusion, retention, and deletion belong in a written agreement your counsel reads, not in a paragraph you have to take on faith. Ask us for those terms in writing — and hold every vendor on your shortlist to the same standard.
Where we are as a company, stated the same way: Available now through a founding pilot program for mid-market B2B companies ($20M–$500M ARR) running Salesforce or HubSpot.
Go deeper
Agentic Readiness Audit
A free assessment across six dimensions — governance, non-human identity, shadow AI, data readiness, workflow suitability, and evidence — returned as a written report within 48 hours of the intake session.
See what the audit covers →What a security review actually checks
The four things a reviewer works from — hosting, the approval gate, audit logging, and identity scoping — written as a checklist you can use against any vendor, including us.
Read the checklist →Governance questions to ask any vendor
The questions worth putting to anyone selling you an AI agent, and what a weak answer sounds like in each case.
Read the questions →For the wider argument about why this operating model replaced fully autonomous agents, see governed autonomy. For how the approval chain gets designed inside your own organisation, see who has to sign off before an AI agent sends.
Bring Security to the readout
The Agentic Readiness Audit assesses governance, non-human identity, shadow AI, data readiness, workflow suitability, and evidence — on your own environment, returned in writing within 48 hours of the intake session. It costs nothing and it is the fastest way to give a reviewer something concrete to evaluate.
Get the free readiness auditFrequently Asked Questions
- Is my data used to train AI models?
- This is the right question to ask any AI vendor, and the answer belongs in a contract rather than on a marketing page. Ask us for the model-training exclusion as a written term during your evaluation — and ask every other vendor on your shortlist for theirs in writing too. A trust page saying it is not the same as an agreement saying it.
- Is MatrixLabX SOC 2 certified?
- Not at the application layer — that work is in progress, and we will not describe it as complete before it is. The SOC 2, ISO 27001, and PCI DSS attestations associated with the platform are held by Google Cloud, which operates the underlying infrastructure. They are real, and they are not ours.
- Can an agent send something or write to my CRM without approval?
- No. Every externally visible action waits for a named human to approve it, and that gate is enforced in the architecture rather than requested in a prompt — there is no code path that delivers an unapproved external action. It is not a setting that can be switched off.
- What happens when an agent gets something wrong?
- If it is wrong before approval, a reviewer rejects it and nothing external happens — the rejection is recorded along with the draft that prompted it. If something was approved that should not have been, the ledger shows the action, the rationale it was based on, and which person approved it, so the review is a factual one rather than a reconstruction.
- What uptime do you commit to?
- An engineered availability SLO of at least 99.5% on the model and inference path, with third-party dependencies named and carved out explicitly. We publish that as an engineering target rather than a contractual SLA, because a number that exceeds the SLAs of the components underneath it is not a commitment anyone can keep.
- Where does PrescientIQ run?
- It is hosted and operated by MatrixLabX on Google Cloud as a multi-tenant service, with per-agent least-privilege identities and prompt-injection defense on every inbound surface. Architecture questions that go deeper than that belong in a conversation with our team rather than on a web page.
- Do you have customer references and measured results?
- We are in a founding pilot program, not years into a mature customer base, so we do not publish measured customer outcome data. That is exactly why the Agentic Readiness Audit is free — it gives you diligence on your own environment instead of asking you to trust a logo wall.
- Who should review this before we buy?
- Bring Security and whoever owns your CRM to the same session. The questions a security review actually asks — where the workload runs, whether the approval gate is enforced, whether actions are logged as they happen, and whether each agent holds a scoped identity — are the ones this page is organised around.
Notes on this page
Every compliance and availability statement above renders from a single claims register rather than being written per page, which is why the same sentences appear verbatim elsewhere on this site. Attestations are attributed to the organisation that holds them. No performance figure, customer outcome, or pricing claim appears on this page. SOC 2, ISO 27001, and PCI DSS attestations are held by Google Cloud, which operates the underlying infrastructure. They are not MatrixLabX certifications. Nothing here is legal or compliance advice; deployment-specific questions should go to your own counsel and to our team in writing.