Security
Agento runs in regulated enterprise environments. This page is the short version of how we secure the platform, where we are on compliance, and how to report a vulnerability.
How we protect your business
Single sign-on
Your team logs in with your existing company sign-on. Multi-factor authentication is enforced for administrators, and new users can be added and removed automatically as your directory changes on Business and Enterprise plans.
Permissions you control
Set exactly who can see and do what, down to individual tools and tasks. Each customer's data stays fully separated from everyone else's, end to end.
Guardrails and approvals
You define the rules and approval steps that govern what the AI is allowed to do. Every action is checked against those rules before it runs, and each decision is recorded.
Reliable automation
Work runs on automation that resumes on its own and never loses progress. Steps pick up exactly where they left off, retries happen automatically, and long-running work survives outages.
Safe hands-on tasks
When the AI needs to operate an app on your behalf, it does so in an isolated, one-time workspace with tightly limited access and a full recording of everything it did.
Complete audit trail
Every step is captured as tamper-evident evidence you can review or hand to auditors. Locked, unchangeable storage is available for regulated record-keeping.
Encryption everywhere
Your data is encrypted in transit and at rest using industry-standard protection. Enterprise customers can bring and manage their own encryption keys.
Protected infrastructure
The platform runs in a locked-down, private environment with no direct exposure of your data. Credentials are stored in a secure vault and never written to logs.
Compliance posture
- SOC 2 Type I: targeted for Q3 2026. Type II audit period scoped to begin once Type I issues.
- ISO 27001: roadmap.
- GDPR / UK GDPR: DPA available; SCCs in place for international transfers.
- Australian Privacy Act / APPs: compliant as a domestic provider.
- HIPAA / PCI: not in scope at GA. Talk to us before processing data covered by these regimes so we can scope the right controls.
- Our controls are aligned to widely recognised security and responsible-AI best-practice frameworks.
Incident response
We operate a 24/7 on-call rotation for production incidents. Customers will be notified of confirmed security incidents affecting their data within the timeframes required by applicable law and our DPA, and in any case without undue delay.
Status: status.agento.au
Vulnerability disclosure
Please report issues to security@agento.com.au. We commit to acknowledging reports within 2 business days, providing an initial assessment within 5 business days, and fixing or mitigating confirmed issues on a timeline proportionate to severity.
We do not currently operate a paid bug bounty programme, but we recognise good-faith research on the same terms as the standard disclosure norms.
Sub-processors
The current sub-processor list is maintained at /trust and updated within 30 days of any material change. Customers on Business and Enterprise plans can subscribe to change notifications.
Trust pack
For procurement, audit, or security review: security questionnaire pack, sub-processor list, DPA template, SOC 2 report under NDA once issued, and pen test attestation under NDA. Request via security@agento.com.au.