Built for enterprise compliance from day one
Your ops workflows touch sensitive financial and HR data. MicroAGI is designed with data residency, encryption, access controls, and audit logging as foundational requirements, not afterthoughts.
Security properties you can document for your InfoSec team
AES-256 encryption at rest
All stored data including workflow definitions, run logs, and connector credentials encrypted at rest using AES-256. Keys managed in a dedicated key management service, rotated quarterly.
TLS 1.2 and 1.3 in transit
All data in transit encrypted using TLS 1.2 minimum. TLS 1.3 preferred. Connections from agents to external systems use mutual TLS where the target supports it.
Data residency in Germany
All data stored and processed in Frankfurt, Germany. No data leaves the EU. Infrastructure provider contractually bound to EU data processing requirements. Data processing agreement available for all customers.
Role-based access control
Granular permissions per user role. Operators, approvers, and administrators have different views and capabilities. Connector credentials scoped to minimum required permissions.
Immutable audit logs
Every agent action, approval decision, configuration change, and login event written to an immutable append-only log. Logs cannot be modified or deleted by any user, including administrators.
Credential isolation
API keys and OAuth tokens stored in an isolated secrets vault, never in workflow definitions, environment variables, or logs. No MicroAGI employee has access to plaintext credentials.
Compliance posture
MicroAGI is a young company and we are transparent about where we are in our compliance journey. We have already built the technical controls that enterprise ops teams need.
GDPR compliant
EU data residency, data subject rights processes, DPA available for all customers, and privacy by design in all data processing workflows. Our privacy policy covers all AI processing activities.
SOC 2 Type II in progress
We are currently undergoing SOC 2 Type II audit with a target completion in the second half of 2026. The underlying technical controls for the audit are in place today.
Penetration testing
Annual third-party penetration test conducted by an independent security firm. Results shared with Enterprise customers under NDA. Remediation tracked and verified.
Infrastructure and operations
Dedicated compute per workspace
Agent runs execute in isolated compute environments. No shared agent execution between customers. Resources de-provisioned after each run.
Network segmentation
Control plane and data plane are network-segmented. Agents run in a restricted execution environment with outbound traffic limited to defined connector endpoints only.
Automated backups
Workflow definitions and run logs backed up daily with 30-day retention. Point-in-time recovery available for Enterprise plans. Backups encrypted using the same AES-256 key management.
Need a security review before you sign?
We are happy to provide a security questionnaire response, a technical architecture document, and a DPA for your procurement process. Enterprise pricing includes an InfoSec call.