Security
How AgentProof protects your data.
AgentProof is a software product that helps you build a compliance-readiness record for your AI agents before your compliance review. This page explains, in plain language, how we look after the data you put into AgentProof: where it is stored, how it is kept separate, and the controls you have over it.
Our security posture
Your data is stored in the European Union
AgentProof stores your account and assessment data in a database located in the European Union. We do not transfer your stored data out of that region as part of normal operation; sign-in emails and calls to Microsoft's own services follow those providers' infrastructure.
Per-account data isolation
Your workspace data is isolated to your account. One customer's agents, answers, evidence, and reports are never shown to another customer.
Immutable, frozen records
Frozen records preserve the assessment and evidence state available when the version was created. AgentProof never edits or silently rewrites an older record. Immutable does not mean indestructible: you can permanently delete your own data from the delete-data page, and a workspace owner can permanently delete the whole workspace and its records.
We do not sell your data
AgentProof does not sell your data, and your account data is not shared with third parties for advertising. It is used to run the assessments you ask for and to produce your reports.
Controls you have over your data
Your data is yours. You can export it (read-only) and delete your own documentation-pack data yourself from your account. A workspace owner can also delete the entire workspace and all its data from workspace settings: the control shows exactly what will be removed, requires a typed confirmation phrase, and records that the deletion happened. You can also ask our team to run and confirm a deletion for you.
Export your data — get a read-only copy of the information held in your account.
Delete your data — remove your documentation-pack data yourself from your account; workspace owners can also delete the entire workspace themselves from workspace settings (typed confirmation, recorded).
Access and accounts
You sign in to AgentProof with your own account, and only signed-in members of your workspace can see your workspace. Operational and administrative tools are kept separate from the customer product and are not reachable from your account.
AgentProof helps you build a compliance-readiness record for your AI agents. It is not legal advice, not a certification, and not an audit. Not regulatory approval. Not vendor endorsement. Live behaviour testing is required before production use.
AgentProof is a software product. This page describes how the product handles your data; it is explicitly not a certification, not an audit, not a SOC 2 report, not a regulatory attestation, not insurance, and not a compliance attestation. We do not claim any such status.
This is the current security information for AgentProof. It is not legal advice. For security or legal correspondence, you can write to [email protected].
Read more about how we handle trust, our Privacy Policy, and our Terms of Service.