Security

How we protect your data and operations.

AIAGENTNET is built on a principle of least privilege. Every AI employee operates inside a declared boundary, every action leaves a receipt, and business data stays in the customer-controlled environment.

Security on the stack

Boundaries, identity, receipts

Permissions, named AI employees, and reviewable records wrap every action from people and AI to your data.

Boundary · identity · receipt chain

AI
AI employee Day-to-day execution running
runs on
Workspace On AgentOS X running
calls tool
Connector Approved tool edge idle
writes receipt
Receipt Reviewable evidence receipted
approves
Human Judgment & approval waiting human
runningblockedwaiting humanreceipted
Identity plane Named AI staff
Your data Records you control
Runtime host Where AI employees act
  • IdentityNamed AI
  • ToolsConnectors
  • PackagesInstall
  • Agent WebOpen edge

Inspect a control

Step 01 of 04

Set permissions

Each AI employee acts only inside the scope you set on the OS.

Replace, for the irreplaceable.

Security practices

What we do today

Permissions per AI employee

Each AI employee only works inside the scope you set. Actions outside that scope are blocked, not just by policy.

Named AI employees on every action

You can see which AI employee acted. AI employees do not hold long-lived bearer tokens; each call is signed on the host and single-use. Product API keys stay separate from AI identity.

Execution records and audit trail

Every AI action leaves a reviewable record: which AI employee, which tools, inputs, outputs and outcome. Records are retained for audit and are not mutable after creation.

Data stays in your environment

Customer records, conversation content and workflow outputs live in the customer-controlled environment. AIAGENTNET keeps account, billing, entitlement and delivery records for authentication, support, invoicing and compliance.

Self-hosted responsibility

For self-hosted AgentOS X, customers are responsible for local host security, backups, network exposure, operating-system patching and user access. AIAGENTNET support follows the order, DPA and support request scope.

TLS in transit

All API traffic between clients and AIAGENTNET services is encrypted over TLS 1.2 or later. Internal service-to-service calls on the same host do not leave the process boundary.

Access control on billing and entitlement

Subscription, entitlement and delivery records are scoped to the authenticated customer account. Cross-account access is prevented at the data layer.

AIAGENTNET MAIL sending compliance

Account verification, billing, support and delivery notifications use AIAGENTNET MAIL. Abuse, spam or unauthorized sending reports should be sent to security@aiagentnet.cloud and support@aiagentnet.cloud.

Acceptable Use enforcement

Agent actions that impersonate humans, bypass permissions, escalate privileges, attack third-party systems or evade audit may be suspended under the Acceptable Use terms.

Subprocessors and service providers

Subprocessors and service providers

Providers that may process limited account, billing, delivery or operational data for AIAGENTNET LLC services. Self-hosted AgentOS X business data stays in the customer environment.

CategoryProvider / role
PaymentsStripe, Inc. — card and bank payment processing for international checkout
CDN / edge securityCloudflare, Inc. — DNS, TLS termination and edge protection for public web traffic
HostingCloud infrastructure providers operating the production nodes that serve www.aiagentnet.cloud and related APIs
EmailAIAGENTNET MAIL (first-party) for transactional mail on AIAGENTNET domains
Analytics (limited)Cloudflare Web Analytics / insights where enabled — no ad cookies by default

Compliance roadmap

Compliance roadmap

Selected programs we are investing in as the product and customer base grow.

StandardStatus
SOC 2 Type IIIn progress
ISO 27001Planned
GDPR data processing agreementAvailable on request via privacy@aiagentnet.cloud
Penetration testingPlanned

Vulnerability disclosure

Vulnerability disclosure

If you discover a security vulnerability in AIAGENTNET products or infrastructure, report it to security@aiagentnet.cloud. We acknowledge reports within 2 business days and aim to resolve confirmed issues within 30 days.