The security page
Our public statement of how customer data is protected — written as capabilities, and ending with a plain list of what we do not offer.
Browse topics
What it is
The security page at agentency.com/security is our public statement of how customer data is protected. It is deliberately written as capabilities rather than badges: every claim names something the platform does today, and the page ends with a plain list of what we do not offer.
That last section is the point of the page. A buyer whose procurement process requires a particular certification should discover that in the first minute, on a public page, rather than several calls into a sales conversation.
When you would use it
Send this link whenever someone asks about your security posture: a procurement questionnaire, an IT review, a manager signing off on a new vendor, or a customer asking where their conversations are stored.
Use it, not this Help Center, for the platform-level answer. Use the Help Center for the settings you operate yourself — enabling two-factor authentication, setting roles, revoking a key, deleting a customer's data.
Where to find it
Open the security page directly, or find Security in the Product column of the footer on every public page. It is not in the top navigation. No account is required.
What you will see
Four groups of capability cards, then the gaps, then a contact block.
Access and account security — two-factor authentication with one-time codes and single-use backup codes, available on every plan including Free; scoped API keys you can create, monitor, and revoke individually; role-based team access with billing reserved to the account owner; and login protection with rate limiting and an authentication audit trail.
How your data is handled — every read and write scoped to the account that owns it; traffic encrypted in transit and channel credentials stored encrypted; your knowledge and conversations used only to answer your own customers, never sold and never shared with other customers; and deletion that really removes a source from the index your chatbot searches.
Privacy controls you operate — configurable conversation retention, erasure or anonymisation of an individual customer's record, consent-gated marketing cookies, and minimal logging.
Guardrails on the AI itself — answers restricted to your own content with a relevance floor so the chatbot declines rather than improvises; validated outbound calls for actions; spend ceilings so a traffic spike stops instead of billing you; and explicit confirmation before high-risk actions run.
What we do not offer yet — published as plainly as the rest. At the time of writing that list includes no SOC 2 or ISO 27001 certification, no single sign-on or automated user provisioning, no choice of data region, no customer-managed encryption keys, and no self-hosted deployment. Read the live page rather than this summary, since it tracks the code.
Questions or a vulnerability report — both go to the support address shown on the page. Disclosure reports are answered first.
Where the Help Center covers the same ground
| On the security page | Here |
|---|---|
| Two-factor authentication, sign-in protection | The Security and sign-in category |
| Roles and who can do what | The Team workspaces category |
| API keys and scopes | Personal access tokens |
| Retention and customer data erasure | The Customers and leads category |
| Spend ceilings and credits | Message credits |
Limits and plan notes
Most of what the page describes is not a paid extra. Two-factor authentication is available on every plan, Free included, and the platform-level protections — account isolation, encryption in transit, the relevance floor, spend ceilings — apply to every account regardless of what you pay.
What your plan does affect is scale: how many team members you can invite and therefore how much role separation is practical. See Plans and what you get.
Common problems
My security questionnaire asks for a certification listed under the gaps.
The answer is on the page and it is honest: we describe our practices, and we have not been audited against those frameworks. Tell us through Contact support — knowing which frameworks customers actually need is how we prioritise.
I need single sign-on for my team.
Not available today. Sign-in is email and password, or Google, with optional two-factor authentication that we strongly recommend enabling for every member. The Security and sign-in category walks through it.
I want to report a vulnerability.
Use the address on the security page rather than the ordinary support form, so it reaches the right people first.
Common questions
Where do I send a security questionnaire?
Read the security page first — it answers most questionnaires directly, including the parts we cannot claim. Anything left over goes to the address published on that page.
Are you SOC 2 or ISO 27001 certified?
No, and the page says so plainly in its own words. We describe our practices; we have not been audited against those frameworks. Tell us if you need one so we can prioritise.
Can I choose which region my data lives in?
Not today. Your account runs in our primary region, and that limitation is listed on the security page rather than left for you to discover in a sales call.
How do I report a vulnerability?
Use the address on the security page rather than the ordinary contact form. Disclosure reports are answered before general security questions.
Was this article helpful?
Related articles
Privacy, terms, and cookies
What each of the three legal pages governs, where they apply between you and us, and where your own customer policy takes over.
The about page
Why Agentency exists and the four commitments the product is designed against — each one visible as behaviour you can observe.
Create a personal access token
Mint a scoped API key on Settings → Developer. The secret is shown once, carries an expiry, and is owner-only.
The features page
What the public features page covers, how it differs from this Help Center, and where each capability is documented.
Ready to try it on your own content?
Create a free workspace, add a document, and ask the questions your team is tired of answering.