Security & data protection
Approach
Agentique deploys AI roles inside the client's existing systems. Personal and other sensitive data is processed under the client's rules; we minimize volume, retention time, and access surface.
Personal and sensitive data
- For pilots and contracts — a separate DPA/SOW: what we process, why, how long we retain it, and who the subprocessors are.
- Decisions about people (hire/reject, payouts, system access) stay with humans; the agent prepares drafts, evidence, and reminders.
- We do not sell personal data. Data subject rights — see our Privacy Policy.
- Roles handling candidates, customers, or internal documents follow role-specific policies; domains are not mixed (e.g. hiring ≠ insurance).
How agents are built
Typical production architecture for AI roles (HR, support, document flow):
- Isolated environment per client — separate execution boundary; one role's data is not mixed with other tenants.
- Network closed by default — external calls only to allowlisted APIs (CRM, ticketing, LLM, storage, etc.).
- Least privilege — API access scoped to the role; separate chats and pipelines per user or manager.
- PII minimization in prompts — for sensitive roles: contact masking before the LLM, local audio transcription where possible, no unnecessary dumps into chat.
- Action logs — operational audit trail for control, incident review, and process improvement.
- Official API integrations — the agent complements your ATS/CRM/HRIS; it does not replace your system of record.
- LLM access runs under your account or a dedicated workspace we manage for you.
- Credentials live in environment variables / a vault — never in your repository or chat history.
Controls
| Area | Practice |
|---|---|
| Access | Role-based; minimal API privileges |
| Transport | TLS for all external calls |
| Personal data | Data minimization; deletion after the pilot on request; no unnecessary copies in chat |
| Chat confidentiality | Separate DM sessions; no shared "main" session across users |
| Pilot data | Scope defined in the SOW; deleted after the pilot on request |
| Incidents | Client notified within 24 hours of detection |
What we don't do
- We don't train public models on client data without written consent.
- We don't move production data into employees' personal accounts.
Security governance
Internal security policy program and audit readiness. We do not claim SOC 2 or ISO certification without an independent auditor's report.
Documents on request
DPA, subprocessor list, and a processing description for the pilot — at hello@agentique.team after a strategy call.