AGCMS

Trust & Security

A public mirror of the in-app Trust Center. The same audit-bundle verifier that auditors use is embedded on the home page — try it.

Security posture

  • SOC 2 Type IIIn observation (Vanta) — report Q3 2026
  • Penetration testScheduled — Cure53, week 14
  • Encryption at restAES-256-GCM via envelope encryption
  • Encryption in transitTLS 1.3 only
  • SSOSAML / OIDC via WorkOS — 40+ identity providers
  • MFATOTP enforced for admin & compliance roles
  • Audit chainHMAC-SHA256, hash-chained, Merkle-anchored to S3 Object Lock
  • Key rotationActive rotation procedure with historical-row verification

Subprocessors

VendorPurposeRegion
AWSCompute, storage, KMS, S3 Object LockUSA / EU
WorkOSSSO / SAML / OIDCUSA
StripeBillingUSA
VantaSOC 2 evidence collectionUSA
Better StackStatus page + ops uptime monitoringUSA
Anthropic / OpenAI / GroqLLM inference (per tenant choice)USA