AAgentProof

Trust Centre

Clear support. Clear limits.

AgentProof helps you build the compliance-readiness record your review needs for every AI agent. This is what it does, what it does not do, and where your data lives. No exaggeration, and no claim it cannot back up.

What AgentProof does

  • Gives you one AI estate inventory across manual, connected, and hybrid environments, with discovered and manually added agents
  • Runs a structured practitioner workflow: intake, quick triage, governance and regulatory lenses, evidence, controls, tests, vendor and model review, decision, and monitoring
  • Records a deterministic readiness score and status as one clearly labelled part of a broader compliance-readiness record
  • Maps documentation and evidence coverage against jurisdiction-aware lenses drawn from EU, UK, US, NIST, ISO 42001, and OWASP
  • Structures your real evidence into an evidence register, control checklist, test pack, vendor and model review, and approval and decision record, and keeps monitoring and incidents current after go-live
  • Keeps unknowns and missing information visible, and flags where legal, privacy, security, or procurement review is recommended
  • Uses Radar to recommend reassessment for the specific agents affected when tracked sources, frameworks, or models change
  • Produces a versioned, review-ready compliance-readiness record per agent that you can take into a compliance review

What AgentProof does not do

  • Not: Certify, accredit, approve, or attest that any agent, system, organisation, or process meets a regulation or standard
  • Not: Provide legal advice on your agents or obligations
  • Not: Provide audit assurance or act as an audit of your controls
  • Not: Issue a numeric rating against a regulation, a pass or fail verdict, or confirm that anything is required by law
  • Not: Grant regulatory approval or endorsement
  • Not: Guarantee that any agent is safe, ready for production, or free of risk
  • Not: Replace your legal, privacy, security, procurement, or risk review
  • Not: Decide on your behalf or silently rewrite existing records or change methodology; Radar recommends reassessment, and the decision to rely on an agent stays with your team

The trust boundary

AgentProof provides AI-agent compliance-readiness and documentation support. It is not certification, legal advice or an audit, and it does not determine that an organisation or AI system is compliant. Legal or specialist review may still be required.

Your privacy in the browser

Your account and assessment data is stored in a database located in the European Union. AgentProof shows readiness summaries and documentation packs; it does not display your access tokens or raw provider payloads in the browser, and one customer's data is never shown to another.

The detail

Every statement here is one AgentProof can stand behind

The plain-language sections below spell out the same commitments in more detail, and a live check re-runs the claim-safety rules on this page every time it renders.

Trust Centre · claim safety

12 plain-language sections

Each section is written in plain language. AgentProof keeps this page free of claims it cannot back up — no certifications, endorsements, or guarantees we do not actually hold.

  • What AgentProof reads

    Read-only metadata: tenant identifiers, environment list, agent list, configuration objects needed to build the canonical agent footprint. Consent is granted through standard Microsoft sign-in with your own account (your tenant admin can additionally grant or revoke organisation-wide consent), and can be revoked at any time.

  • What AgentProof does not read

    AgentProof does not automatically read business records, conversation content, or transactional data from your connected systems - the connector reads environment, agent and configuration metadata only. It never reads model weights, payment data, or contract content. Information you deliberately enter (agent descriptions, assessment answers, named owners) is stored as part of your record.

  • Read-only connector posture

    The Microsoft connector is used only to read metadata - environment lists, agent lists, and the configuration needed to build the agent footprint. AgentProof does not write to or change your tenant, and consent can be revoked at any time from your Microsoft admin centre. Tokens never leave the server.

  • Workspace isolation

    Every workspace is isolated to its owner. One customer's connector state, assessment facts, reports, and improvement actions are never visible to another customer.

  • Demo and sample separation

    Sample agents always carry a Sample or Demo badge. Sample data cannot enter a real workspace without that badge. Real workspaces start empty and only ever show real data the workspace owner has authorised.

  • Authentication model

    Magic-link sign-in by default, with no third-party trackers. A small number of accounts may set a password as an alternative.

  • Data handling principles

    Your account and assessment data is stored in a database located in the European Union and is isolated to your own account. AgentProof does not send your data to any third-party AI provider unless you explicitly configure one.

  • Microsoft endorsement

    AgentProof is not endorsed by Microsoft. References to Microsoft Power Platform, Copilot Studio, Azure AI Foundry, or Entra ID describe public Microsoft surfaces only — AgentProof does not speak on behalf of Microsoft.

  • Legal and certification claims

    AgentProof does not claim ISO 27001, SOC 2, GDPR, HIPAA, FedRAMP, or any other certification. AgentProof is not legal advice. AgentProof provides a compliance-readiness and evidence-coverage view — it shows what is in place and what is missing.

  • Revocation awareness

    Any consent you grant AgentProof can be revoked at any time through your Microsoft tenant admin console (or equivalent for other providers). AgentProof refuses to operate on a revoked connector.

  • Audit-friendly design

    Every discovered fact records where it came from (a real connection, your own confirmation, or a manual entry). Reports carry a version stamp and methodology version, and connection changes are recorded.

  • AI provider usage boundaries

    AgentProof does not contact any third-party AI provider unless one is explicitly configured. Where a text narrative is generated, the deterministic readiness score is computed without any AI model and cannot be overridden by one.

Every statement on this page is one AgentProof can stand behind.