Skip to main content

Trust Center

The straight answers your security and procurement teams need: how your data is handled, where we stand on compliance, the third parties involved, and how to report a security concern. No spin.

How your data is handled

What happens when Agento does a piece of work for you. Every step stays within your guardrails, is captured for your records, and can be traced back through a complete audit trail.

  1. 1. Your systems stay the source of truth

    Agento works with the tools you already use, like Procore, SharePoint, and Salesforce. Your data stays in your systems. We only handle what a given task actually needs, nothing more.

  2. 2. Secure, controlled access to your tools

    Agento securely connects to all your tools through a single, monitored access point. Sign-in credentials are stored in a protected vault, kept separate from the AI, and scoped to each individual project.

  3. 3. Work runs inside guardrails you set

    Every task runs within the permissions, approval rules, and boundaries you define. Nothing steps outside the limits you've put in place.

  4. 4. Reliable automation that never loses work

    Long-running work is saved as it goes. If something interrupts a task, it resumes on its own from where it left off, rather than starting over or losing progress.

  5. 5. A complete, tamper-evident audit trail

    Every action is recorded as a clear, verifiable record you can review at any time, and delivered into the monitoring and reporting tools your team already relies on.

Compliance posture

The plain version. We will not claim a certification we do not hold.

Independent security audits

In progress

We engage third-party assessors to review our controls across access management, change management, and incident response, and are working toward recognised industry certifications.

Information security management

Readiness work underway

A formal security management program is in development, covering risk assessment, control documentation, and ongoing internal review.

Regulated & government workloads

In progress

We're building toward the assurance frameworks that regulated and government customers require. Documentation available to design partners under NDA.

Privacy & data protection

Compliant

We comply with applicable privacy laws in the regions we operate, including breach notification obligations. Privacy contact: privacy@agento.com.au.

International data transfers

Safeguards available on request

Standard contractual protections are in place for any cross-border transfer of customer data.

Sub-processors

The third parties that touch customer data. Customers on Business and Enterprise plans can subscribe to change notifications and we publish material changes within 30 days.

Provider

Purpose

Cloud infrastructure provider (Australian region)

Hosting, storage, and core infrastructure, kept in Australia

Workflow automation service

Runs long-running automations reliably so no work is lost

AI model providers

Power the AI behind each task; Agento automatically uses the best AI for each job, and you can restrict which providers are used

Payment processor

Billing and payment processing

Product analytics service

Usage insights from signed-in workspaces to improve the product

Content delivery & security network

Fast, secure delivery and protection against attacks

Vulnerability disclosure

Report security issues to security@agento.com.au. We acknowledge within 2 business days, provide an initial assessment within 5 business days, and remediate confirmed issues on a timeline proportionate to severity.

We do not currently operate a paid bug bounty program. Good-faith research is welcome on the standard disclosure norms.

DPA on request

Our Data Processing Addendum is available to any prospective customer on request. It incorporates standard international transfer safeguards for cross-border data transfers.

Email legal@agento.com.au with your entity name and we will return the current DPA within one business day.

Trust pack for procurement

For procurement, audit, or security review, we provide a packaged set: security questionnaire responses, current sub-processor list, DPA template, independent audit report under NDA once issued, and pen test attestation under NDA. Email security@agento.com.au.