SOC 2 Type 1, today.
Independent audit of our security controls — access, change management, monitoring, incident response. Report available on request under NDA.
Agents touch your live tools. Stripe, HubSpot, GitHub, your codebase, your customers. We treat that boundary with the seriousness it deserves. Isolated workspaces. Encrypted everything. No training on your data. Confirmation before anything irreversible.
Independent audit of our security controls — access, change management, monitoring, incident response. Report available on request under NDA.
Information security management system implementation underway. Gap assessment complete, internal audit Q2 2026, certification target end of 2026.
Aligned with Singapore Personal Data Protection Act. Data Protection Officer registered. DPIA workflow for any client engagement touching personal data.
Every connection — your browser to our edge, our agents to your tools, agents to LLMs — runs over TLS 1.2+. No plaintext on the wire, ever. HSTS enforced on all customer surfaces.
Industry-standard AES-256 encryption on all stored data — conversation history, tool credentials, intermediate state, generated artifacts. Per-workspace encryption keys, rotated quarterly.
Hard technical boundary between client workspaces. No shared compute, no shared storage, no shared identity. An agent in workspace A cannot read, write, or even enumerate anything in workspace B. This is enforced at the infrastructure layer, not just the application.
We do not use your conversations, your data, or your workflows to train models. Not ours, not third-party providers. Our LLM contracts (Anthropic, OpenAI, regional) explicitly opt out of training on customer data. Full stop.
Default retention is 90 days of conversational history, indefinite for artifacts you choose to keep. Full workspace wipe available via support — removes stored data, learned context, and integration history within 30 days. Tombstones audit-logged.
Every agent action — tool call, message sent, external write — is logged with actor, target, payload digest, and outcome. Logs are immutable, retained 12 months by default, exportable on request. Enterprise tier gets streaming SIEM forwarding.
Every action,
attributable.
What the agent ran, what it touched, what shipped — surfaced in one rolling pulse. Immutable, exportable, SIEM-forwardable on Enterprise.
May closed up 18% MoM — driven by 4 mid-market closes in SG/MY. Burn held flat despite the ops hire. Pipeline weighted at SGD 1.2M with three enterprise in legal review. Runway shortens by a month from April; conservative new-deals model puts it back at 16 by July.
Per-user isolation inside a shared workspace. Your DMs with the agent stay yours — teammates can't see them even with admin access.
RBAC on agent capabilities. Map your Slack / WhatsApp roles to what the agent will do for them. Finance role gets finance tools, engineering gets engineering tools.
When the agent calls Stripe on a teammate's behalf, it uses their token, not a shared one. Full attribution, full audit trail, full PDPA alignment.
Bring your own KMS key. Encryption keys for your workspace held in your AWS / GCP account, not ours. Available on Enterprise.
PII tagging, redaction policies, configurable retention per data class. Built for regulated SEA businesses — fintech, healthtech, gov.
Type 2 covers 6+ months of operating effectiveness. ISO 27001 certification body audit. Both reports usable in your enterprise procurement.
SOC 2 Type 1 report, sub-processor list, security questionnaire, DPA — available on request under mutual NDA. Usually back within two business days.