Product Solutions Developers Pricing Trust Verify a receipt
Public · Trust Center

Trust Center

Everything a security, procurement, or compliance reviewer needs in one place: our security posture, honest compliance status, who we rely on, the data-control options you can turn on, and the full legal suite. Where we say “in progress,” we mean it — no badge we haven’t earned. And where words aren’t enough, you can verify our receipts yourself.

// Security posture

How your data is protected

The claims below are drawn straight from our contractual commitments in the MSA and DPA — not marketing. They are what we sign up to, in writing.

๐Ÿ”’
Encryption in transit & at rest
Customer Data is encrypted in transit (TLS 1.2+) and at rest. Prompt and response content stays out of the ledger by default — the operator records only hashes and metering.
โ–ฆ
Tenant isolation
Each tenant is logically isolated; Customer Data is never visible to another tenant or partner.
โฑ
72-hour breach notification
We commit to notifying affected customers of a personal-data breach within 72 hours, per the DPA.
โ›“
Independently-verifiable audit trail
Every governed action is a hash-chained receipt whose Merkle root is anchored on a public blockchain — your auditor recomputes the proof without trusting us. Verify one →

Full terms govern in the MSA and DPA; the summaries above are for orientation and do not modify those agreements.

// Compliance status

Certifications & posture — stated honestly

“In progress” means an audit is genuinely underway, not a badge we’re implying. We publish only what is true today.

SOC 2 Type IIIn progress

Observation window open; report expected 2026.

ISO 27001In progress

Stage 1 readiness underway.

HIPAAOn request

BAA available for healthcare pilots.

EU AI ActLogging ready

Article 12 record-keeping built in; high-risk obligations apply Aug 2026.

SOC 2 is the single compliance-status headline we make, and it reads “in progress” everywhere on this site, including our footer. No certification, customer name, or statistic on this page is fabricated.

// Data controls

Options you can turn on

Depending on your plan, the following data-control options are available and configurable in Console → Settings. These are real switches, not future promises dressed as certifications.

๐ŸŒ
Data residency
Choose where the control-plane records live, configurable per tenant in Console → Settings.
๐Ÿ”‘
BYOK
Bring your own key for the data you control — residency, retention and BYOK sit together in Settings.
๐Ÿข
Sovereign / self-host plane
Run the ledger and anchoring in your own VPC; only the leaf hash and metering numbers cross to the Agentics control plane. The data-plane split →
// Sub-processors

Who we rely on

The sub-processors below handle the control plane the operator runs on. By default, prompt and response content is never handed to them — only hashes and metering.

Sub-processorPurposeData handled
NetlifyStatic hosting & edge functionsRequest metadata
Public blockchain (Solana)Merkle-root anchoringRoot hashes only
Managed PostgresReceipt ledger & meteringHashes & metering
Model providersInference (your chosen vendors)Your prompts, per your config

Self-host customers replace the ledger and anchoring with their own infrastructure. The current sub-processor baseline mirrors the Trust portal; material changes are reflected there and in the DPA.

// Legal & agreements

The full legal suite

Every agreement, published and readable. These govern; the summaries elsewhere on this page are orientation only.

Don’t take our word for any of this.

Our real differentiator is that you never have to. Every governed action produces a receipt whose proof you recompute yourself against a public chain we don’t control. Paste a hash and check the math.

Verify a receipt →