Everything your security team needs for vendor review. We believe trust is earned through transparency, not marketing.
AgentGate is a stateless validation API. Agent output is processed in-memory and never written to disk or database.
| Data type | Storage | Retention |
|---|---|---|
| Raw agent output | Not stored — in-memory only | — |
| Validation metadata (domain, tier, timestamps) | Encrypted at rest | 90 days (Free) / 12 months (Paid) |
| SHA-256 gate hashes | Encrypted at rest | 90 days (Free) / 12 months (Paid) |
| Audit evidence packages | Encrypted at rest, exportable as JSON | 90 days (Free) / 12 months (Paid) |
| API keys | Hashed (bcrypt) | Active account lifetime |
| Account data (email) | Encrypted at rest | 30 days post-closure |
| Server access logs | Log aggregator | 30 days |
| Billing records | Stripe / payment processor | 7 years (legal obligation) |
crypto.timingSafeEqual) to prevent timing attacks.ag_live_ / ag_test_, scoped per account. Keys are shown once on creation.Strict-Transport-Security — HSTS with 1-year max-ageX-Content-Type-Options: nosniffX-Frame-Options: DENYX-XSS-Protection: 1; mode=blockContent-Security-Policy — restrictive CSP on all pages| Standard | Status |
|---|---|
| GDPR | Designed for compliance |
| CCPA | Designed for compliance |
| SOC 2 Type II | On roadmap |
| ISO 27001 | Planned |
| PCI-DSS | Payment processing via Stripe (PCI Level 1) |
We use honest language: "designed for compliance" means we follow the principles and controls, but have not yet undergone formal certification audits. We will update this page as certifications are obtained.
| Provider | Purpose | Data processed | Location |
|---|---|---|---|
| Supabase | Database, authentication | Account data, validation metadata | US / EU |
| Stripe | Payment processing | Billing data (no raw API data) | US |
| Google Analytics | Usage analytics | Anonymized page views, events | US |
| SendGrid | Transactional email | Email addresses, message content | US |
We will notify customers 30 days before adding new subprocessors that handle personal data.
Preparing for enterprise procurement? We can provide:
Email bakhrom@agengate.com with subject "Vendor Pack Request" and we will respond within 2 business days.