Governance & Trust Center
How we keep AI agents safe to run on your systems: the principles we design to, the controls we build, how we handle data, and what we can share with your security, legal and procurement teams.
Three Governance Principles
Least-privilege access
Each agent can reach only the systems, data and actions its workflow needs, through governed service accounts and credentials.
Human oversight
Consequential decisions and high-impact actions wait for approval by a named person, with clear escalation paths.
Observability
Prompts, tool calls, parameters, outputs and human approvals are logged, so every action can be traced, reviewed and, where needed, rolled back.
Agent Security Controls
These are the controls we design and document for each engagement. The implementation and testing status of each control for your system is set out in your proposal and reports.
Identity & access
Agent identity and service-account governance; least-privilege tool permissions; authentication and secrets management.
Action boundaries
Human approval for high-impact actions; transaction and action allowlists; maximum execution steps and cost limits.
Input & output safety
Controls against prompt injection, including indirect injection through documents and web content; output validation; data-loss prevention.
Assurance
Evaluation of models and tools, and red-team testing proportionate to the use case, before and after go-live.
Operations
Monitoring and incident response; rollback and emergency shutdown; logging of prompts, tool calls, parameters, outputs and human approvals.
Third parties & MCP
Controls over sub-processors and model providers; for MCP, we define which servers, tools, data and actions are exposed, and how they are authenticated.
How We Handle Data
Isolation
Client data is isolated per engagement and environment.
Encryption
Data is encrypted in transit and at rest, using configurations agreed with your security team.
Residency
We select models, hosting and storage to meet your data-residency requirements for the USA, Canada, the UK or elsewhere.
Retention & deletion
Retention periods for application data, model-provider logs, vector stores and backups are documented per engagement, with deletion at the end of the engagement or on request.
Model training
We configure model providers so that your data is not used to train their models wherever the provider supports it, and we document the settings used.
Logging with care
Logs can contain sensitive data, so access to them is restricted and their retention is agreed with you.
Frameworks, Documents and Legal
Frameworks we design for
We build systems to support your obligations under frameworks such as GDPR, UK GDPR, CCPA, PIPEDA, HIPAA, PCI DSS, SOC 2, ISO 27001 and the NIST Cybersecurity Framework. These are frameworks we design for, not certifications held by Agentic Resources. Compliance with each framework remains your organization’s responsibility, and we work within your certified environments.
Available on request
- Mutual non-disclosure agreement (NDA)
- Data processing agreement (DPA)
- List of sub-processors and model providers used for your engagement
- Responses to your security questionnaire
- Legal entity details for supplier onboarding
Legal advice
We are not a law firm and do not provide legal advice. We work alongside your compliance team and counsel.
Privacy
See our Privacy Notice and Cookie Policy for how we handle personal data collected through this website.
Talk to Us About Your Governance Requirements
Bring your security, legal or procurement questions to a free 30-minute AI Opportunity Review.