Agentic Resources

Get Started

AI

Start with a free 30-minute AI Opportunity Review

Book a Consultation →
Agentic Resources

We fix the process first, then automate it with governed AI agents.

How We Engage ↗

Get Started

AI

Start with a free 30-minute AI Opportunity Review

Book a Consultation →

Governance & Trust Center

How we keep AI agents safe to run on your systems: the principles we design to, the controls we build, how we handle data, and what we can share with your security, legal and procurement teams.

Three Governance Principles

Least-privilege access

Each agent can reach only the systems, data and actions its workflow needs, through governed service accounts and credentials.

Human oversight

Consequential decisions and high-impact actions wait for approval by a named person, with clear escalation paths.

Observability

Prompts, tool calls, parameters, outputs and human approvals are logged, so every action can be traced, reviewed and, where needed, rolled back.

Agent Security Controls

These are the controls we design and document for each engagement. The implementation and testing status of each control for your system is set out in your proposal and reports.

Identity & access

Agent identity and service-account governance; least-privilege tool permissions; authentication and secrets management.

Action boundaries

Human approval for high-impact actions; transaction and action allowlists; maximum execution steps and cost limits.

Input & output safety

Controls against prompt injection, including indirect injection through documents and web content; output validation; data-loss prevention.

Assurance

Evaluation of models and tools, and red-team testing proportionate to the use case, before and after go-live.

Operations

Monitoring and incident response; rollback and emergency shutdown; logging of prompts, tool calls, parameters, outputs and human approvals.

Third parties & MCP

Controls over sub-processors and model providers; for MCP, we define which servers, tools, data and actions are exposed, and how they are authenticated.

How We Handle Data

Isolation

Client data is isolated per engagement and environment.

Encryption

Data is encrypted in transit and at rest, using configurations agreed with your security team.

Residency

We select models, hosting and storage to meet your data-residency requirements for the USA, Canada, the UK or elsewhere.

Retention & deletion

Retention periods for application data, model-provider logs, vector stores and backups are documented per engagement, with deletion at the end of the engagement or on request.

Model training

We configure model providers so that your data is not used to train their models wherever the provider supports it, and we document the settings used.

Logging with care

Logs can contain sensitive data, so access to them is restricted and their retention is agreed with you.

Frameworks, Documents and Legal

Frameworks we design for

We build systems to support your obligations under frameworks such as GDPR, UK GDPR, CCPA, PIPEDA, HIPAA, PCI DSS, SOC 2, ISO 27001 and the NIST Cybersecurity Framework. These are frameworks we design for, not certifications held by Agentic Resources. Compliance with each framework remains your organization’s responsibility, and we work within your certified environments.

Available on request

  • Mutual non-disclosure agreement (NDA)
  • Data processing agreement (DPA)
  • List of sub-processors and model providers used for your engagement
  • Responses to your security questionnaire
  • Legal entity details for supplier onboarding

Legal advice

We are not a law firm and do not provide legal advice. We work alongside your compliance team and counsel.

Privacy

See our Privacy Notice and Cookie Policy for how we handle personal data collected through this website.

Talk to Us About Your Governance Requirements

Bring your security, legal or procurement questions to a free 30-minute AI Opportunity Review.