Agentshield

AI agent security platform

AI Agent Security Platform: our security posture and data handling.

Security buyers check this page before they sign up, and they should. Here is exactly how Agentshield handles your data and how we are built. Plain answers, no hype.

OWASP LLM Top 10 EU AI Act-ready Immutable audit trail

In one line

Agentshield inspects and governs agent traffic to enforce your policy and write an immutable audit trail. It never trains on your data, encrypts everything, runs least-privilege internally, and you stay in control of every action and your retention.

Data handling

How we handle your data.

We never train on your data

Your agent traffic, policies, and audit records are never used to train models, ours or anyone else's. Agentshield inspects to enforce policy; it does not collect your content to build a model.

Inspection, not collection

We process the agent traffic we need to enforce your policy and write the audit trail. We are the control layer, not another model that wants your data.

Encryption in transit and at rest

All data is encrypted in transit with TLS and at rest. Secrets are stored in a dedicated secrets manager, never in plaintext.

Least-privilege access

Internal access to systems is least-privilege and audited. No engineer has standing access to customer agent traffic.

Tamper-evident audit trail

The audit trail itself is append-only and cryptographically sealed, so the record of what happened cannot be quietly altered.

You control retention

You set how long audit and inspection data is retained, and you can request deletion. Data residency options are available on higher tiers.

Compliance

Compliance direction, stated honestly.

SOC 2. We hold no SOC 2 attestation today and no audit is underway. We would rather say that plainly than imply a certification we do not have. Our current security documentation is available under NDA to customers on Scale and Enterprise plans.

EU AI Act. The Act's high-risk obligations require record-keeping and human oversight. Agentshield's immutable audit trail and human-approval gates are built to provide exactly that evidence. We are not a law firm and this is not legal advice, but the controls map to the requirements reviewers ask about.

OWASP Top 10 for LLM Applications. Our controls map to the canonical risk taxonomy for this space, from prompt injection through missing accountability.

Subprocessors and DPA. We maintain a current subprocessor list and a Data Processing Addendum, available to customers. Data residency and on-prem or VPC deployment are available on higher tiers for teams with isolation requirements.

Vendor review

The security questionnaire, answered up front.

These are the questions that come back on almost every vendor security review. Rather than make you send the spreadsheet first, here are the answers. If your questionnaire has something not covered here, ask and you will get a direct answer rather than a marketing one.

Reviewer question Our answer
Where is customer data processed and stored? In US regions on our managed infrastructure by default. Data residency and dedicated single-tenant deployment are available on higher tiers, and on-prem or VPC deployment keeps agent traffic entirely inside your own network boundary.
Do you use customer data to train models? No. Not for our models, not for any third party. Agent traffic, policies, and audit records are used to enforce your policy and produce your trail, and for nothing else. This is a contractual commitment, not a setting.
Is data encrypted in transit and at rest? Yes, TLS in transit and encryption at rest across every store. Secrets live in a dedicated secrets manager and are never written in plaintext to configuration, logs, or the audit trail.
What internal access do your employees have? Least-privilege and audited. No engineer holds standing access to customer agent traffic. Access requires an approved, time-bound grant that is itself recorded.
Can the audit trail be altered? No. It is append-only and cryptographically sealed, so a record cannot be quietly edited or removed after the fact. That property is what makes it usable as evidence rather than as a dashboard.
How long is data retained, and can we delete it? You set the retention window, and you can request deletion. Shorter retention is a common answer to a reviewer question, and we would rather you set it deliberately than inherit a default.
Do you have a DPA and a subprocessor list? Yes, both are current and available to customers. The subprocessor list is maintained rather than assembled on request, so it reflects what is actually in the path today.
What happens if Agentshield is unavailable? You choose the failure mode per policy: fail closed, where agent actions stop, or fail open, where they proceed unenforced and are flagged. Regulated deployments almost always choose fail closed, and we recommend stating your choice in your own review documents.

The controls above are what we run on our own platform. What we sell is the equivalent set for your agents: per-agent identity and scope, injection inspection, human approval on irreversible actions, and the same kind of append-only trail. If you are assembling that program internally, zero trust for AI agents lays out the sequence, and enterprise AI agent security covers what review boards ask for.

FAQ

Common questions about Agentshield security.

Is Agentshield secure?

Agentshield encrypts data in transit and at rest, never trains on customer data, runs least-privilege audited internal access with no standing engineer access to agent traffic, and writes an append-only cryptographically sealed audit trail. We hold no SOC 2 attestation today and will not imply otherwise.

Does Agentshield train on our data?

No. Your agent traffic, policies, and audit records are never used to train any model, ours or a third party's. Agentshield inspects traffic to enforce your policy and write your audit trail, then stops. It is a control layer, not a product that needs your content to improve a model.

Is Agentshield SOC 2 certified?

No. We hold no SOC 2 attestation and no audit is underway, and we would rather say that plainly. What is in place: encryption in transit and at rest, least-privilege audited internal access, and an append-only sealed audit trail. Treat any vendor that answers this question vaguely as answering no.

Can Agentshield run on-premise or in our own VPC?

Yes, on higher tiers. On-prem and VPC deployment keep agent traffic inside your own network boundary, which is the usual answer when data residency or a no-external-control-plane requirement would otherwise block the deployment. Data residency options are available separately.

What compliance frameworks does Agentshield help with?

The controls map to the evidence requirements in the EU AI Act for record-keeping and human oversight, to the OWASP Top 10 for LLM Applications risk taxonomy, and to the audit and access-control expectations in sector rules such as HIPAA and FFIEC. We provide the controls and the evidence; we are not a law firm and this is not legal advice.

How do you handle a security vulnerability report?

Report it to our security contact and you will get a human acknowledgement. We triage, fix, and tell affected customers what happened. We do not require a researcher to sign a non-disclosure agreement before we will look at a report, because that practice suppresses the reports you most need to receive.

Security teams approve agents they can govern.