1. Architecture & Data Flow

AgentGate is a stateless validation API. Agent output is processed in-memory and never written to disk or database.

What we store

Data typeStorageRetention
Raw agent outputNot stored — in-memory only
Validation metadata (domain, tier, timestamps)Encrypted at rest90 days (Free) / 12 months (Paid)
SHA-256 gate hashesEncrypted at rest90 days (Free) / 12 months (Paid)
Audit evidence packagesEncrypted at rest, exportable as JSON90 days (Free) / 12 months (Paid)
API keysHashed (bcrypt)Active account lifetime
Account data (email)Encrypted at rest30 days post-closure
Server access logsLog aggregator30 days
Billing recordsStripe / payment processor7 years (legal obligation)

2. Encryption

3. Authentication & Access Control

4. Infrastructure

5. Security Headers & Protections

6. Compliance Posture

StandardStatus
GDPRDesigned for compliance
CCPADesigned for compliance
SOC 2 Type IIOn roadmap
ISO 27001Planned
PCI-DSSPayment processing via Stripe (PCI Level 1)

We use honest language: "designed for compliance" means we follow the principles and controls, but have not yet undergone formal certification audits. We will update this page as certifications are obtained.

7. Subprocessors

ProviderPurposeData processedLocation
SupabaseDatabase, authenticationAccount data, validation metadataUS / EU
StripePayment processingBilling data (no raw API data)US
Google AnalyticsUsage analyticsAnonymized page views, eventsUS
SendGridTransactional emailEmail addresses, message contentUS

We will notify customers 30 days before adding new subprocessors that handle personal data.

8. Incident Response

9. Data Subject Rights

10. Vendor Assessment

Preparing for enterprise procurement? We can provide:

Request a vendor pack

Email bakhrom@agengate.com with subject "Vendor Pack Request" and we will respond within 2 business days.