AgentOS

Trust center

Built for supervision

AI that acts on client accounts must be inspectable. Every change is proposed, approved, and logged.

The approval architecture

This is our real security story — not a badge wall.

  1. 01

    Propose

  2. 02

    Approve

  3. 03

    Execute

  4. 04

    Log

Data handling

Plain English. Claims below track current product behavior; model training/retention language is finalized with engineering before any absolute marketing claim ships.

What we accessGoogle Search Console, GA4, and Google Ads via OAuth for properties you connect — scoped per client workspace.
What we storeWorkspace configuration, recommendation history, approval decisions, and audit logs needed to operate the product.
What we never doWe do not invent unsupervised live changes. Agents propose; humans approve. Training / retention claims require engineering sign-off before we state them as absolute.

Permissions and tenancy

Workspaces are isolated. Full seats operate the product; viewer seats are read + Ask only (matrix truth — not a second full seat). Autonomy dial and audit log ship on every tier.

Subprocessors and model providers

Infrastructure and model providers are listed honestly in Privacy as they are contracted. If a training/retention answer is not yet contractually clean, we say what is true today — we do not ship fake certainty.

Read the Privacy Policy →

Roadmap honesty

  • SOC 2: Not completed. Stated intent; no badge until held.
  • Penetration test: Not published. No fake report links.
  • DPA: Available when the first Partner conversation requires it (/dpa).

Never ship a compliance logo we don’t hold.

  • Every change is proposed, approved, and logged.
  • Questions about trust? Talk to us.