Skip to main content
TomorrowX
SolutionsData Mediation™PlatformPerspectivesCompanyLet’s talk
SolutionsData Mediation™PlatformPerspectivesCompanyLet’s talk
Site information/Trust & Assurance

Company

Trust & Assurance

How we build, secure and license the Composable Agentic Platform — stated plainly, verifiable independently.

Last updated: 20 August 2026

AWS Foundational Technical Review

AWS Qualified Software badgeThe Composable Agentic Platform (CAP) has passed the AWS Foundational Technical Review and carries the AWS Qualified Software designation. The FTR assesses software against AWS Well-Architected practices for security, reliability and operational excellence.

Open source compliance — OpenChain ISO/IEC 5230

OpenChain ISO/IEC 5230 conformance badgeTomorrowX is an OpenChain conformant organisation ↗. Our open source licence compliance program conforms to ISO/IEC 5230:2020, the international standard for open source licence compliance.

Every CAP distribution ships with generated LICENSE and NOTICE attribution, verbatim licence texts, and a written source offer for LGPL components fulfilled through our public LGPL source repository ↗. Our open source policy is published in the product documentation.

Software bill of materials

Every CAP release includes a complete Software Bill of Materials in CycloneDX format, generated at build time and shipped inside the distribution. Customers can inventory every component we ship — direct and transitive — without asking us.

Secure development

CAP is developed against the NIST Secure Software Development Framework (SSDF, SP 800-218). We maintain a practice-by-practice evidence map and can provide a CISA Secure Software Development Attestation on request. Our pipeline runs static analysis (CodeQL), dependency vulnerability scanning, container scanning and licence gates on every build, and our security baseline is maintained at zero open high or critical findings.

Platform hardening is aligned to the controls of the Australian Government Information Security Manual (ISM) at PROTECTED level, including AES-256-GCM authenticated encryption of credentials at rest with per-installation keys.

Release integrity

Published releases include SHA-256 checksums for all artifacts. Container images are delivered through digest-verified registries; machine images are distributed through the AWS Marketplace with pinned image identifiers.

Reporting a vulnerability

Email notices@tomorrowx.com with details of the product, version and steps to reproduce. We acknowledge reports within 5 business days and deliver fixes through our standard release channels. See our responsible disclosure policy and the security policy published with our public repositories ↗.

Licensing

CAP is commercial software licensed under the TomorrowX End User Subscription Licence Agreement, available through selected Cloud Marketplaces. Third-party software disclosures are published in the product documentation and shipped with every distribution.

TomorrowX

Data Mediation — the control architecture for governed, sovereign and repeatable enterprise AI at scale.

Begin

Explore solutionsDiscover Data MediationExplore the platformExplore perspectives

Platform

Composable Agentic Platform
Programmable Data AgentEditorConsole
Licensing and support

Programmes

Proof of Capability and ValueX Labs ↗PartnersPartner Portal ↗

Company

Our storyResearch and historyPeopleLet’s talk
TomorrowX © 2006–2026
PrivacyTermsAccessibilitySecurityTrust
Tomorrow, today.