Privacy Policy
AgentProof Privacy Policy
This policy explains, in plain English, what data AgentProof handles, where it is stored, how it is used, and the controls you have over it.
1. What data we handle
- Your account sign-in identity, which is managed by the authentication provider.
- The agents you describe.
- Agent versions and the inputs and evidence you submit.
- The readiness records and documentation packs that are generated.
- Your export history.
- Deletion-log and audit entries that record data-rights actions.
- Your workspace and its membership.
- If you connect Microsoft: an encrypted connection credential (server-only, never shown in the browser), environment summaries, and the agents discovered in your tenant.
- Curated monitoring (Radar) records, which contain no customer business data.
2. Where your data is stored
Your account and assessment data is stored in a database located in the European Union. Your data is isolated to your own account, so one customer's agents, inputs, and reports are not visible to another customer.
3. Your data rights and controls
When you are signed in, AgentProof gives you direct controls over your data:
Export your data
From your export page you can download a JSON archive of your data. Your sign-in account itself is managed by the authentication provider and is not included in the archive.
Delete your data
From the delete-data page you can permanently delete your agents, their versions and submitted inputs — after typing a confirmation phrase. If you are the workspace owner, this also permanently deletes the entire workspace: its readiness records and documentation packs, environments, connections, reports, and other members' access. If you are not the workspace owner, ask the owner or write to [email protected] to remove workspace-level records. It does not delete your sign-in account, your retention preference, or your audit logs, and it cannot be undone.
Choose a retention policy
From the retention page you can choose what happens to the inputs you submit. There are three policies: keep inputs until you delete them (the default), delete inputs immediately after scoring, or make inputs eligible for purge 30 days after submission (automatic purge is not yet enabled — until then, eligible inputs are purged on request, or when you delete the version or your data). A policy applies to new agents you create afterwards; it does not retroactively purge older versions.
4. How we use your data
We use the data you provide to run the assessment and to produce and store your documentation pack. Documentation packs are kept immutable so your history is preserved and your progress is a real record rather than something rewritten after the fact.
5. Sharing
We do not sell your data. If you connect Microsoft (currently the only connector), AgentProof reads environment, agent and configuration metadata only — it does not read or extract your business records, and it does not write to or change your tenant.
6. Contact
Questions about your data or this policy? Visit our help centre to get in touch. For privacy or data requests, you can write to [email protected]; for legal correspondence about this policy, write to [email protected].
This is the current Privacy Policy. It is a data-rights foundation, not legal advice.
See also our Terms of Service, Refund Policy, and Pricing.
Your account and assessment data is stored in a database located in the European Union and is isolated to your account.