TRUST CENTER

What we do with your data.

agentwach watches autonomous agents on behalf of teams that cannot afford to be wrong about who has access to what. Here is exactly how we handle the data you send us.

Compliance posture

SOC 2 Type II

In progress

Controls aligned to the Trust Services Criteria; external audit scheduled.

HIPAA

Designed to support

Architecture supports teams preparing for HIPAA workflows. BAA available on the Business plan.

ISO 27001

Designed to support

Information-security controls mapped; certification not yet held.

GDPR

Compliant

EU-region database hosting, DPA available, data-export and deletion endpoints.

Subprocessors

VendorPurposeRegion
SupabasePrimary database, auth, file storageEU (Frankfurt)
CloudflareCDN, edge compute, DDoS protectionGlobal
StripePayment processing and billingUS / EU
ResendTransactional email deliveryUS
OpenAI / Anthropic / GoogleOptional model providers for diagnose featureUS

Encryption & retention

  • · API keys stored as SHA-256 hashes; raw keys never persisted server-side.
  • · All traffic encrypted in transit (TLS 1.3) and at rest (AES-256).
  • · Event retention defaults to 14 days on Free, 30 days on Team, 90 days on Business.
  • · Workspace deletion purges all events, agents, and token usage within 30 days.

Security contact

Report a vulnerability to security@agentwach.com. We acknowledge within one business day.

Need a DPA, BAA, or completed security questionnaire? Contact sales.