Skip to content
The Agentency website4 min read

The security page

Our public statement of how customer data is protected — written as capabilities, and ending with a plain list of what we do not offer.

Browse topics

What it is

The security page at agentency.com/security is our public statement of how customer data is protected. It is deliberately written as capabilities rather than badges: every claim names something the platform does today, and the page ends with a plain list of what we do not offer.

That last section is the point of the page. A buyer whose procurement process requires a particular certification should discover that in the first minute, on a public page, rather than several calls into a sales conversation.

When you would use it

Send this link whenever someone asks about your security posture: a procurement questionnaire, an IT review, a manager signing off on a new vendor, or a customer asking where their conversations are stored.

Use it, not this Help Center, for the platform-level answer. Use the Help Center for the settings you operate yourself — enabling two-factor authentication, setting roles, revoking a key, deleting a customer's data.

Where to find it

Open the security page directly, or find Security in the Product column of the footer on every public page. It is not in the top navigation. No account is required.

What you will see

Four groups of capability cards, then the gaps, then a contact block.

Access and account security — two-factor authentication with one-time codes and single-use backup codes, available on every plan including Free; scoped API keys you can create, monitor, and revoke individually; role-based team access with billing reserved to the account owner; and login protection with rate limiting and an authentication audit trail.

How your data is handled — every read and write scoped to the account that owns it; traffic encrypted in transit and channel credentials stored encrypted; your knowledge and conversations used only to answer your own customers, never sold and never shared with other customers; and deletion that really removes a source from the index your chatbot searches.

Privacy controls you operate — configurable conversation retention, erasure or anonymisation of an individual customer's record, consent-gated marketing cookies, and minimal logging.

Guardrails on the AI itself — answers restricted to your own content with a relevance floor so the chatbot declines rather than improvises; validated outbound calls for actions; spend ceilings so a traffic spike stops instead of billing you; and explicit confirmation before high-risk actions run.

What we do not offer yet — published as plainly as the rest. At the time of writing that list includes no SOC 2 or ISO 27001 certification, no single sign-on or automated user provisioning, no choice of data region, no customer-managed encryption keys, and no self-hosted deployment. Read the live page rather than this summary, since it tracks the code.

Questions or a vulnerability report — both go to the support address shown on the page. Disclosure reports are answered first.

Where the Help Center covers the same ground

On the security pageHere
Two-factor authentication, sign-in protectionThe Security and sign-in category
Roles and who can do whatThe Team workspaces category
API keys and scopesPersonal access tokens
Retention and customer data erasureThe Customers and leads category
Spend ceilings and creditsMessage credits

Limits and plan notes

Most of what the page describes is not a paid extra. Two-factor authentication is available on every plan, Free included, and the platform-level protections — account isolation, encryption in transit, the relevance floor, spend ceilings — apply to every account regardless of what you pay.

What your plan does affect is scale: how many team members you can invite and therefore how much role separation is practical. See Plans and what you get.

Common problems

My security questionnaire asks for a certification listed under the gaps.

The answer is on the page and it is honest: we describe our practices, and we have not been audited against those frameworks. Tell us through Contact support — knowing which frameworks customers actually need is how we prioritise.

I need single sign-on for my team.

Not available today. Sign-in is email and password, or Google, with optional two-factor authentication that we strongly recommend enabling for every member. The Security and sign-in category walks through it.

I want to report a vulnerability.

Use the address on the security page rather than the ordinary support form, so it reaches the right people first.

Common questions

Where do I send a security questionnaire?

Read the security page first — it answers most questionnaires directly, including the parts we cannot claim. Anything left over goes to the address published on that page.

Are you SOC 2 or ISO 27001 certified?

No, and the page says so plainly in its own words. We describe our practices; we have not been audited against those frameworks. Tell us if you need one so we can prioritise.

Can I choose which region my data lives in?

Not today. Your account runs in our primary region, and that limitation is listed on the security page rather than left for you to discover in a sales call.

How do I report a vulnerability?

Use the address on the security page rather than the ordinary contact form. Disclosure reports are answered before general security questions.

Was this article helpful?

Ready to try it on your own content?

Create a free workspace, add a document, and ask the questions your team is tired of answering.