What happens at 2am
when it breaks.
Autonomous agents running your workflows are only as good as what happens when one stops. This is the whole answer — what we do today, and what we are still building. The two are marked separately on purpose.
What we do today
We watch it, around the clock
Legion Force AI monitors deployed agents remotely around the clock — health checks, error rates, and performance metrics, with alerting on anomalies. A Legion Force engineer is in the loop for anything outside normal operating parameters.
We patch it remotely, on an announced schedule
Legion Force AI pushes patches and updates remotely on a pre-announced, SLA-backed schedule. Clients approve the maintenance window before any patch is applied.
When something breaks, a human is committed to it
Legion Force AI maintains a written incident response playbook and a committed Legion Force support role, with response tiers for system-down and degraded incidents. The specific response times are committed in your contract.
You hold every key to your data
The client holds every encryption key to their data, for every current deployment model. Legion Force AI has zero unilateral unlock capability — we cannot access, decrypt, or recover client data or systems without the client.
What that means for you: Because Legion Force AI holds no keys, the client is solely responsible for key backup, rotation, and escrow. This also means Legion Force AI cannot unlock a client system on the client's behalf if keys are lost — the client's own key management practice is load-bearing.
What we are building next
Stated as intent, not as shipped behaviour. If you are evaluating us against a compliance requirement, assume only the section above.
Self-healing first, humans last
Autonomous self-healing and self-defending deployments (our Sentinel project's design goal) — agents detect and remediate common failure modes without waiting for a human. Human intervention becomes the last resort, not the first response.
Zero-downtime updates with automatic rollback
Zero-downtime rolling updates with automatic rollback if a post-patch health check fails.
Autonomous-first incident response
Autonomous-first incident response — agents attempt self-remediation before any human is paged. Humans remain the last resort, engaged only when autonomous recovery cannot resolve the incident.
Autonomous self-healing is a roadmap goal, not current capability. Current deployments rely on Legion Force AI remote monitoring plus committed human incident response — see operability.monitoring and incidentResponse above.
The incident response SLA applies to production deployments under contract. Pilot-period response is best-effort, not SLA-backed.
Got a requirement this doesn't answer?
Your compliance officer can get a full security and operations briefing during scoping — including anything above that needs to be written into a contract.