Independent security audits
In progressWe engage third-party assessors to review our controls across access management, change management, and incident response, and are working toward recognised industry certifications.
The straight answers your security and procurement teams need: how your data is handled, where we stand on compliance, the third parties involved, and how to report a security concern. No spin.
What happens when Agento does a piece of work for you. Every step stays within your guardrails, is captured for your records, and can be traced back through a complete audit trail.
1. Your systems stay the source of truth
Agento works with the tools you already use, like Procore, SharePoint, and Salesforce. Your data stays in your systems. We only handle what a given task actually needs, nothing more.
2. Secure, controlled access to your tools
Agento securely connects to all your tools through a single, monitored access point. Sign-in credentials are stored in a protected vault, kept separate from the AI, and scoped to each individual project.
3. Work runs inside guardrails you set
Every task runs within the permissions, approval rules, and boundaries you define. Nothing steps outside the limits you've put in place.
4. Reliable automation that never loses work
Long-running work is saved as it goes. If something interrupts a task, it resumes on its own from where it left off, rather than starting over or losing progress.
5. A complete, tamper-evident audit trail
Every action is recorded as a clear, verifiable record you can review at any time, and delivered into the monitoring and reporting tools your team already relies on.
The plain version. We will not claim a certification we do not hold.
Independent security audits
In progressWe engage third-party assessors to review our controls across access management, change management, and incident response, and are working toward recognised industry certifications.
Information security management
Readiness work underwayA formal security management program is in development, covering risk assessment, control documentation, and ongoing internal review.
Regulated & government workloads
In progressWe're building toward the assurance frameworks that regulated and government customers require. Documentation available to design partners under NDA.
Privacy & data protection
CompliantWe comply with applicable privacy laws in the regions we operate, including breach notification obligations. Privacy contact: privacy@agento.com.au.
International data transfers
Safeguards available on requestStandard contractual protections are in place for any cross-border transfer of customer data.
The third parties that touch customer data. Customers on Business and Enterprise plans can subscribe to change notifications and we publish material changes within 30 days.
Provider
Purpose
Cloud infrastructure provider (Australian region)
Hosting, storage, and core infrastructure, kept in Australia
Workflow automation service
Runs long-running automations reliably so no work is lost
AI model providers
Power the AI behind each task; Agento automatically uses the best AI for each job, and you can restrict which providers are used
Payment processor
Billing and payment processing
Product analytics service
Usage insights from signed-in workspaces to improve the product
Content delivery & security network
Fast, secure delivery and protection against attacks
Report security issues to security@agento.com.au. We acknowledge within 2 business days, provide an initial assessment within 5 business days, and remediate confirmed issues on a timeline proportionate to severity.
We do not currently operate a paid bug bounty program. Good-faith research is welcome on the standard disclosure norms.
Our Data Processing Addendum is available to any prospective customer on request. It incorporates standard international transfer safeguards for cross-border data transfers.
Email legal@agento.com.au with your entity name and we will return the current DPA within one business day.
For procurement, audit, or security review, we provide a packaged set: security questionnaire responses, current sub-processor list, DPA template, independent audit report under NDA once issued, and pen test attestation under NDA. Email security@agento.com.au.