Security & Trust

Built for teams that can't afford to move fast and break things.

Your Slack conversations, competitor research, and growth decisions pass through us. Here's exactly how we protect them.

Contact security teamRequest DPA
Encryption

Encrypted in transit, encrypted at rest

Every byte of your data is encrypted end-to-end. We use industry-standard primitives — no in-house cryptography.

  • TLS 1.3 for all traffic between your browser, our servers, and your dedicated runtime
  • AES-256-GCM at rest for stored credentials and connector secrets
  • Scrypt password hashing using OWASP-recommended parameters
  • HMAC-SHA256 signed session cookies, rotated on each sign-in
Customer isolation

Each customer runs on its own instance

Your data never shares a process with another customer. Every customer gets a dedicated, isolated agent runtime with its own workspace, memory, and data store.

  • A dedicated runtime process per customer — no shared compute, no shared event loop
  • A separate, single-customer data store — no shared tables, no noisy-neighbor queries
  • A private workspace per customer — your company profile and every agent's memory live inside it only; no shared memory or cross-customer learning
  • Cross-customer access checks in every read and write — a single contract, enforced system-wide
  • Operator access requires device-bound cryptographic identity — a stolen token alone cannot elevate privileges
Access control

Least-privilege from day one

Employees access customer data only when needed to operate the service.

  • Role-separated authentication (operator vs customer) enforced at the middleware layer
  • Session binding to device identity for operator-scope actions
Data lifecycle

You own your data, and you can take it with you

Your findings, briefings, approvals, and evidence chains belong to you. We store them, we don't license them.

  • Full data export in JSON on request
  • 30-day retention after cancellation, then cryptographic purge
  • No training of AI models on customer content, ever
  • Standard Contractual Clauses for any cross-border data transfer
Compliance

Standards we hold ourselves to,
with status in the open.

SOC 2 Type II
In progress
Pursuing certification · report available under NDA once issued
GDPR
In progress
Working toward full alignment · DPA available to all paid customers
CCPA
In progress
Consumer rights honored today · see Privacy Policy for your rights
ISO 27001
Planned
Evaluating certification for 2026
HIPAA
Not covered
We are not a Business Associate · do not send us PHI
Operations

The boring work that
keeps the lights on.

Per-customer isolation

Every customer runs on a dedicated runtime with its own data store — no shared process, no noisy neighbors.

Encrypted secrets

Connector tokens and gateway credentials are encrypted at rest with AES-256-GCM, with encryption keys kept separate from the data store.

Vulnerability management

Dependencies are kept current and monitored for known advisories; security-relevant updates are prioritized.

Secure SDLC

Code review required for every change. No force-push to main.

Pinned runtime builds

Production runs a vetted, pinned runtime build — every upgrade is regression-tested before promotion.

Subprocessors

Every third party we use,
named and accountable.

We notify paid customers at least 30 days before adding a new subprocessor. Existing customers can object in writing; if we can't find an alternative, you may terminate for cause.

Vendor
Purpose
Region
Railway
Cloud hosting infrastructure
US / EU
Cloudflare
CDN, DDoS protection, WAF
Global edge
Google (Gemini)
LLM inference (default provider)
US / EU
DeepSeek
LLM inference (optional, customer-selectable)
CN
NVIDIA
LLM inference (optional, customer-selectable)
US
Resend
Transactional email
US
Stripe
Billing and payment processing
US / EU / SG
Composio
Managed OAuth for third-party integrations
US
PostHog
Product + website analytics
US / EU
Responsible disclosure

Found a vulnerability? Tell us first.

Email us at [email protected]. We acknowledge within one business day, investigate in good faith, and publicly credit you when the fix ships (unless you ask otherwise). No legal action against good-faith researchers.

Report a vulnerability

Last reviewed: 2026-07-17 · questions? [email protected]

Security & Trust · AgentCeres