Trust & Security Center

Agentic Cloud Solutions' compliance posture, data handling practices, security disclosure process, and sub-processor list — in one place for procurement teams.

Compliance

We are building toward these certifications. We will not claim attainment we haven't achieved.

SOC 2 Type II

Status: In Progress. Audit in preparation. Report will be made available to enterprise prospects under NDA once complete.

PCI-DSS

Status: Planned. Required for AFP (Financial Platform) and relevant Self-Managed deployments. Scoping begins once AFP enters development.

Data Handling & Residency

AEP Self-Managed deployments support air-gapped environments — your data never leaves your cluster. No external calls are made without explicit configuration. For SaaS deployments (Q4 2026), data residency options and sub-processor contracts will be published ahead of GA.

Air-Gapped Self-Managed

Enterprise Self-Managed supports fully offline deployments with a signed license file — no outbound calls required post-activation.

Data at Rest & In Transit

All data encrypted at rest (AES-256) and in transit (TLS 1.2+). Key management documentation available on request.

Security Disclosure

We operate a responsible disclosure program. If you discover a potential security vulnerability in any Agentic Cloud product, please report it to security@agenticcloudsolutions.com. We commit to acknowledging receipt within 2 business days and providing a remediation timeline within 10 business days.

Do not disclose vulnerabilities publicly until we have had an opportunity to remediate them. We will credit researchers who report valid issues.

Sub-Processor List

[Sub-processor list placeholder — to be published before SaaS GA (Q4 2026). Will include names, locations, and data categories for each third-party processor.]

Request Security Documentation

Enterprise and Self-Managed prospects can request our security questionnaire responses, penetration test summaries, and SOC 2 report (when available).

Request Documentation