Permissions per AI employee
Each AI employee only works inside the scope you set. Actions outside that scope are blocked, not just by policy.
Security
AIAGENTNET is built on a principle of least privilege. Every AI employee operates inside a declared boundary, every action leaves a receipt, and business data stays in the customer-controlled environment.
Security on the stack
Permissions, named AI employees, and reviewable records wrap every action from people and AI to your data.
Boundary · identity · receipt chain
Security controls
Identity & connectors
AI staff are named; extra tools stay under your control.
Open docsInspect a control
Step 01 of 04
Each AI employee acts only inside the scope you set on the OS.
Step 02 of 04
Each action is tied to a named AI employee—not an anonymous bot.
Step 03 of 04
Actions leave reviewable receipts on workspace and data.
Step 04 of 04
Business data stays in environments you control.
Replace, for the irreplaceable.
Security practices
Each AI employee only works inside the scope you set. Actions outside that scope are blocked, not just by policy.
You can see which AI employee acted. AI employees do not hold long-lived bearer tokens; each call is signed on the host and single-use. Product API keys stay separate from AI identity.
Every AI action leaves a reviewable record: which AI employee, which tools, inputs, outputs and outcome. Records are retained for audit and are not mutable after creation.
Customer records, conversation content and workflow outputs live in the customer-controlled environment. AIAGENTNET keeps account, billing, entitlement and delivery records for authentication, support, invoicing and compliance.
For self-hosted AgentOS X, customers are responsible for local host security, backups, network exposure, operating-system patching and user access. AIAGENTNET support follows the order, DPA and support request scope.
All API traffic between clients and AIAGENTNET services is encrypted over TLS 1.2 or later. Internal service-to-service calls on the same host do not leave the process boundary.
Subscription, entitlement and delivery records are scoped to the authenticated customer account. Cross-account access is prevented at the data layer.
Account verification, billing, support and delivery notifications use AIAGENTNET MAIL. Abuse, spam or unauthorized sending reports should be sent to security@aiagentnet.cloud and support@aiagentnet.cloud.
Agent actions that impersonate humans, bypass permissions, escalate privileges, attack third-party systems or evade audit may be suspended under the Acceptable Use terms.
Subprocessors and service providers
Providers that may process limited account, billing, delivery or operational data for AIAGENTNET LLC services. Self-hosted AgentOS X business data stays in the customer environment.
| Category | Provider / role |
|---|---|
| Payments | Stripe, Inc. — card and bank payment processing for international checkout |
| CDN / edge security | Cloudflare, Inc. — DNS, TLS termination and edge protection for public web traffic |
| Hosting | Cloud infrastructure providers operating the production nodes that serve www.aiagentnet.cloud and related APIs |
| AIAGENTNET MAIL (first-party) for transactional mail on AIAGENTNET domains | |
| Analytics (limited) | Cloudflare Web Analytics / insights where enabled — no ad cookies by default |
Compliance roadmap
Selected programs we are investing in as the product and customer base grow.
| Standard | Status |
|---|---|
| SOC 2 Type II | In progress |
| ISO 27001 | Planned |
| GDPR data processing agreement | Available on request via privacy@aiagentnet.cloud |
| Penetration testing | Planned |
Vulnerability disclosure
If you discover a security vulnerability in AIAGENTNET products or infrastructure, report it to security@aiagentnet.cloud. We acknowledge reports within 2 business days and aim to resolve confirmed issues within 30 days.
Vulnerability reports, security incidents, abuse reports