Security & Compliance
Last reviewed: September 23, 2026
Our clients trust us with their calls, their customers, and the systems their business runs on. This page describes how we protect that data today — only controls that are in place now, nothing aspirational. Our client portal and platform are in pre-launch development; the controls below are built into them today and are what our SOC 2 audit covers. Live control status and security documentation are in our Trust Center.
Compliance programs
SOC 2
Audit in progressOur controls are monitored continuously in Vanta as we work toward our SOC 2 audit. We will publish the report status here when it is issued.
HIPAA
Program in progressWe are implementing the administrative, physical, and technical safeguards of the HIPAA Security Rule as part of our compliance program. HIPAA has no official certification — any vendor claiming to be “HIPAA certified” is misdescribing it.
Encryption
- All traffic to our website, client portal, and platform is encrypted in transit with TLS 1.2 or higher. Older protocols (TLS 1.0 and 1.1) are refused.
- Data at rest is encrypted with AES-256 by our hosting and database providers.
- Client operational data is additionally encrypted at the application layer with AES-256-GCM, using a separate encryption key for each client. The master key that protects those keys is rotated on a scheduled basis.
- API keys we issue are never stored in plain text — we keep only a one-way keyed hash.
Access control
- Multi-factor authentication is required for every user of the Agentic client portal.
- Two-factor authentication is required for every member of our source code organization.
- Access to production systems is granted through a logged request process, to named individual accounts — no shared logins — and removed when it is no longer needed.
- Each client's data is isolated from every other client's.
Change management
- Every change to our production applications goes through a pull request, and automated tests must pass before it can merge.
- Direct pushes, force-pushes, and branch deletion are blocked on production branches.
Vulnerability management & monitoring
- Dependencies are scanned automatically for known vulnerabilities, with security updates raised as they are published.
- Our public applications are scanned with OWASP ZAP.
- Application errors and service health are monitored continuously, and alerts go to our team in real time.
Incident response
- We maintain a documented Incident Response Plan, approved by management and reviewed every year.
- Automated monitoring alerts our team to errors, failed data writes, and service health problems as they happen.
- If an incident affects your data, we will notify you without undue delay and in line with our contractual and legal obligations.
Infrastructure & data handling
- Our applications and databases are hosted in US data centers (US East).
- Production databases are backed up automatically every day.
- Clients can export their data at any time. When an engagement ends, we return your data and delete it from our systems.
- We do not sell client data.
- A current list of our subprocessors is available on request.
Where our security information lives
- This page — how we protect client data, and the status of our compliance programs.
- Trust Center — live status of our security controls, monitored continuously in Vanta, and security documents available on request.
- Privacy Policy — what personal information we collect and your rights over it.
- Terms of Use — the terms that govern use of this site.
- security@becomeagentic.ai — security questions, questionnaires, and vulnerability reports.
Report a security issue
If you believe you have found a vulnerability in any Agentic system, email security@becomeagentic.ai with the details. Please give us a reasonable chance to fix it before disclosing it publicly. The same address handles security questionnaires and requests for our subprocessor list.
