Legal

Security

How Agent Ai protects your data and infrastructure.

Last updated:January 15, 2025
Effective:January 15, 2025

Our Commitment

At Agent Ai, security is foundational to everything we build. We employ industry-leading practices to protect your data, infrastructure, and applications.

Certifications and Compliance

We maintain the following certifications:

  • SOC 2 Type II — Annually audited by an independent third party
  • GDPR Compliant — Full compliance with EU data protection regulations
  • CCPA Compliant — California Consumer Privacy Act compliance
  • HIPAA Ready — Available for healthcare customers (Enterprise plan)

Infrastructure Security

Cloud Infrastructure

Our services are hosted on AWS in geographically distributed data centers with:

  • 99.99% uptime SLA
  • Automatic failover and disaster recovery
  • 24/7 monitoring and incident response
  • DDoS protection via AWS Shield

Network Security

  • All traffic encrypted with TLS 1.3
  • Web Application Firewall (WAF) protection
  • Network segmentation and least-privilege access
  • Regular vulnerability scanning

Data Protection

Encryption

  • In transit: TLS 1.3 with perfect forward secrecy
  • At rest: AES-256 encryption for all stored data
  • Key management: AWS KMS with automatic rotation
  • Backups: Encrypted and stored in separate regions

Data Isolation

Each customer's data is logically isolated using row-level security and tenant identifiers, preventing any cross-customer access.

Access Controls

Authentication

  • Multi-factor authentication (MFA) available for all accounts
  • SSO/SAML integration with major identity providers
  • Strong password requirements
  • Automatic session timeouts

Authorization

  • Role-based access control (RBAC)
  • Principle of least privilege
  • Granular permission controls
  • Audit logs for all access events

Employee Security

All Agent Ai employees:

  • Pass background checks before hiring
  • Complete annual security training
  • Sign confidentiality agreements
  • Use hardware security keys for production access
  • Follow strict access review processes

Incident Response

We maintain a comprehensive incident response plan:

  1. Detection — 24/7 monitoring and alerting
  2. Response — On-call team responds within 15 minutes
  3. Containment — Isolate and mitigate impact
  4. Investigation — Root cause analysis
  5. Notification — Affected customers notified within 72 hours
  6. Remediation — Implement preventive measures

Vulnerability Disclosure

We welcome reports of security vulnerabilities. Please email security@default.com with details.

We commit to:

  • Acknowledging your report within 24 hours
  • Investigating and responding within 5 business days
  • Crediting researchers (with permission) in our hall of fame

Bug Bounty Program

We run a private bug bounty program through HackerOne. Contact security@default.com to request an invitation.

Compliance Documents

Available upon request:

  • SOC 2 Type II report
  • Penetration testing summary
  • Security questionnaire (CAIQ)
  • Data Processing Agreement (DPA)
  • Business Associate Agreement (BAA) for HIPAA customers

Status and Transparency

Contact

Security questions or concerns: security@default.com