Trust & security
AgentCompliant is built from the ground up with security-first architecture for enterprises that can't afford to compromise on AI governance.
Security architecture
Encryption, identity, auditability, and isolation are first-class — not bolted on after the fact.
AES-256 at rest, TLS 1.3 in transit.
Sensitive fields encrypted with industry-standard algorithms.
Clerk-powered RBAC with org-level isolation.
Least-privilege defaults for every user and service account.
Append-only audit tables with hash chain verification.
Tamper-evident history across engines and gateway events.
Bearer token + API key dual auth on all endpoints.
Scoped keys with plan-aware rate limits at the gateway.
Per-organization schema isolation.
No cross-tenant leakage — every query scoped by org.
OCI cloud with VPC isolation.
Automated backups and monitored availability targets.
Compliance frameworks
Hover a badge for the full framework name. Roadmap items are planned attestations and programs.
Data handling
Sub-processors
Infrastructure
Responsible AI
Bias monitoring — continuous signals and evaluations to surface drift and unfair outcomes before they reach production scale.
Explainability — traceable decisions and documented reasoning paths so teams can answer “why” for auditors and executives.
Human-in-the-loop (HITL) — approvals and escalations where autonomy must yield to human judgment.
Kill switch — instant containment when risk exceeds policy, with audit evidence of who acted and when.
Start a trial or talk to us about architecture reviews, DPA terms, and enterprise deployment options.