Agent360 implements a multi-layered security program to protect customer data, aligned with industry best practices.
Last updated: March 19, 2026
Technical safeguards
In transit
All data is transmitted over HTTPS using TLS 1.2+ encryption, securing communication between users, our servers, and any external services.
At rest
Data stored in our database and infrastructure is encrypted using industry-standard encryption (AES-256 or equivalent), managed by the platform.
Access control
Access is restricted through role-based permissions, so only authorized users and services can access sensitive information.
No sensitive logging
We do not store sensitive data in application logs or monitoring tools.
AI processing controls
We limit what is sent to AI providers, enable zero data retention where available, and can tokenize identifiable fields when appropriate.
Program highlights
Encryption in transit (TLS) and at rest by infrastructure providers.
Tenant isolation via row-level security and scoped tokens.
Least-privilege access, MFA for admin access, and credential rotation.
Audit logging, monitoring, and incident response procedures.
Secure development lifecycle, code review, and dependency scanning.
Business continuity
Regular backups with tested restoration procedures. Region-level provider resilience as available.
Reporting
Report a security issue to [email protected]. Please include steps to reproduce and relevant details. We will acknowledge receipt and provide updates as appropriate.