Trust Center
Security and privacy for every conversation
How Agntix protects the calls, transcripts and data that run through your AI agents — and an honest view of where our compliance program stands today.
Compliance
We only show a certification as achieved once an independent report or certificate exists. Everything below is an honest status as of today.
- In progress
GDPR
EU / EEA
Data processing, data subject rights and international transfer controls designed to GDPR requirements.
Deletion & export controls in progress
- In progress
UAE PDPL
United Arab Emirates
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
Deletion & export controls in progress
- In progress
KSA PDPL
Saudi Arabia
Personal Data Protection Law, as enforced by SDAIA.
Deletion & export controls in progress
- In progress
SOC 2 Type II
Independent audit of security, availability and confidentiality controls over an observation period.
Target: Q1 2027
- In progress
ISO/IEC 27001
Information security management system.
Target: Q2 2027
- On roadmap
HIPAA
United States
Safeguards for protected health information.
- Planned
ISO/IEC 42001
AI management system.
Security overview
Controls that protect the platform and the conversations running on it.
Encryption in transit
The platform is designed to use TLS for traffic to the platform.
Encryption at rest
Encryption at rest for primary databases and object storage.
Access control
SSO for staff tools; access reviews are part of our SOC 2 programme.
Monitoring
Centralised logging, metrics and alerting across services, and a public status page hosted independently of our infrastructure.
Penetration testing
An external penetration test is planned ahead of launch. We'll share a summary on request once it's complete.
Tenant isolation
Customer data is logically separated by organisation. We're completing an access-control hardening programme ahead of our external penetration test.
Data handling & retention
What we store, where, and for how long.
Data residency
Customer data is processed and stored primarily in the United States (AWS us-east-1). Arabic speech processing by Munsit, a CNTXT group company, runs in the European Union (Google Cloud, Belgium). Regional hosting is on our roadmap.
Recordings and transcripts
Retention controls for recordings and transcripts are being built. Nothing is deleted on a schedule today. Requests about specific data go to privacy@agntix.ai and are reviewed case by case. Delivering recordings to a customer-owned storage bucket is available on request for enterprise plans (to confirm).
Deletion and data subject requests
Self-serve deletion and data subject request workflows are being built; we can't yet promise complete, automated deletion. Send requests to privacy@agntix.ai and our team will review each one and tell you what we can do today.
Backups
Databases are backed up, with encryption at rest. Backup retention periods are being confirmed.
AI & data use
How customer data interacts with the models behind your agents.
No training on customer data
We don't train models on customer data. We're confirming data-use and retention terms with each model provider.
Model providers
Agents can run on third-party models or on Agntix self-hosted models. Each provider is listed as a subprocessor.
Human oversight
Live calls can be monitored and taken over by a human operator; every call keeps a full transcript and turn-level trace.
Subprocessors
Pending legal reviewCompanies that may process customer data to deliver the service. Entries marked Affiliate are CNTXT group companies rather than third parties.
Swipe the table sideways to see purpose, data and location.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| MunsitAffiliate · CNTXT group | Arabic speech-to-text and text-to-speech | Call audio, transcripts, agent response text | European Union (Google Cloud, Belgium) |
| Amazon Web Services | Primary hosting: compute, databases, object storage, recordings | All customer data categories | United States (us-east-1) |
| LiveKit | Real-time media, SIP connectivity, call recording egress, turn detection | Call audio, recordings in transit, phone numbers, agent text | To be confirmed |
| Deepgram | Speech-to-text and text-to-speech | Call audio, transcripts | To be confirmed |
| OpenAI | Language models, speech and embeddings | Transcripts and messages, call audio, extracted call data, knowledge base content | To be confirmed |
| Google (Gemini, Speech, reCAPTCHA) | Language models, call-audio analysis, call evaluation (Gemini), speech, bot protection | Call audio, recordings, transcripts, extracted call data, agent configuration and test conversations; device and IP signals (reCAPTCHA) | To be confirmed |
| Microsoft Azure | Speech services and voice infrastructure (to confirm) | Call audio, transcripts | To be confirmed |
| Cohere | Search result reranking for knowledge bases | Knowledge base content, search queries | To be confirmed |
| Google Cloud Platform | Hosting for demo and pilot environments | Data in demo and pilot environments | To be confirmed |
| Anthropic | Language models, including the Copilot assistant (Claude) | Transcripts and messages, extracted call data, knowledge base content, account data retrieved by Copilot | To be confirmed |
| ElevenLabs | Text-to-speech | Agent response text | To be confirmed |
| Cartesia | Text-to-speech | Agent response text | To be confirmed |
| Twilio | SIP trunking, phone numbers, WhatsApp messaging | Call audio, phone numbers, WhatsApp messages and media | To be confirmed |
| RunPod | GPU hosting for Agntix self-hosted speech and language models | Call audio, transcripts, extracted call data, phone numbers | To be confirmed |
| Clerk | User authentication and organisations | Names, emails, IP and device data | To be confirmed |
| Vercel | Dashboard hosting | Names, emails, transcripts, recordings and phone numbers rendered in the dashboard; IP | United States |
| Cloudflare | DNS, edge network, static asset storage, bot protection (Turnstile) on our public forms | IP (where traffic is proxied); IP and browser signals (Turnstile) | To be confirmed |
| Datadog | Logs, traces, metrics, and real-user monitoring of the embedded chat widget | IP and device data, including end-user sessions of the embedded chat widget; transcripts and phone numbers may appear in logs | European Union |
| Slack | Routing in-product feedback to our team | Reporter name, email and organisation; feedback text | To be confirmed |
| GitHub | Tracking in-product feedback as issues | Reporter name, email and organisation; feedback text | To be confirmed |
| Stripe | Subscriptions and billing | Payment data, names, emails, billing address | To be confirmed |
| Svix | Webhook delivery to customer endpoints | Phone numbers, call summaries and extracted data, recording links, session metadata | To be confirmed |
| OpenMeter | Usage metering | Account and session identifiers, usage figures | To be confirmed |
| Tuner | Call quality analysis (where enabled) | Transcripts, recording links, extracted call data, call metadata | To be confirmed |
| n8n Cloud | Sign-up and feedback workflows | Names, emails, phone numbers, company details, feedback | To be confirmed |
This list is being finalised with legal review. We'll announce changes to our subprocessors 30 days in advance.
Documents
Policies and reports. Private documents are marked “Coming soon” until they exist; security questionnaires can be requested now.
Frequently asked questions
Are you SOC 2 certified?
Not yet. Our SOC 2 Type II audit is in progress and our target for the report is Q1 2027. Until then we're happy to answer security questionnaires — use the request form below.
What does “Aligned” mean?
When we describe a framework as Aligned, our controls and processes are designed to meet its requirements. It is not a certification or third-party attestation. No framework is marked Aligned today.
Where is my data stored?
Primarily in the United States (AWS us-east-1). Arabic speech processing by Munsit, a CNTXT group company, runs in the European Union (Google Cloud, Belgium), and some other subprocessors process data in other locations — see the subprocessors list. Regional hosting is on our roadmap.
How do I report a vulnerability?
Email security@agntix.ai. See our responsible disclosure policy below and /.well-known/security.txt.
Can I get your security documentation?
Public documents are linked below. Private documents such as our penetration test summary and security policies are being prepared and will be shared under NDA once available. In the meantime, send us your security questionnaire through the request form.
Responsible disclosure
If you believe you've found a security vulnerability in Agntix, please email security@agntix.ai with steps to reproduce. We will acknowledge your report within three business days and keep you informed while we fix it.
- Give us reasonable time to remediate before public disclosure.
- Don't access or modify other customers' data, degrade the service, or use social engineering.
- We won't pursue legal action for good-faith research that follows this policy.