Security & trust

You are handing agents access to real accounts

That deserves a straight answer about where your data goes, what an agent can touch, and what we have not built yet.

Where your data lives

Your account, agents, chats and memories are stored in a managed Postgres database on Azure, in the Central India region.

  • Every table holding your data that the app’s API can reach is protected by row-level security, so a query only ever returns your own rows. Internal workflow-state tables are not exposed to the API at all.
  • Most documents your agents create are written to your own Google Drive, not to our storage.
  • Files we do store — profile images, and media staged for publishing to social platforms — sit in shared Azure Blob Storage containers. They are served from unlisted links: anyone who has a file’s exact link can open it, but the containers cannot be browsed.
  • The database, its backups and file storage are encrypted at rest by Azure, and all traffic to the app is over TLS.

Credentials and secrets

The tokens that let an agent act on your behalf are encrypted before they are stored, with a key the database never sees.

  • Integration tokens are encrypted at rest with AES-256-GCM, an authenticated cipher, so tampering is detectable rather than silent.
  • Encryption keys and all platform secrets live in Azure Key Vault and are delivered at runtime. Nothing is baked into the application image.
  • Sign-in runs on Supabase Auth, which we host ourselves. Passwords are stored only as bcrypt hashes, never in plain text.

What an agent is allowed to reach

Connecting a tool and authorising an agent to use it are two separate decisions. Connecting Slack does not give every agent Slack.

  • Each agent holds explicit per-integration grants. An agent with no grant for a tool cannot call it, regardless of what it is asked to do.
  • Revoking a connection drops every grant that depended on it, immediately and everywhere.
  • Publishing actions — posting to LinkedIn or Instagram, changing Meta ad campaigns — require your approval by default. On scheduled and other unattended runs they wait in your Approvals inbox until you decide.
  • Every run is metered against your plan’s token allowance, which you can watch from your dashboard.
Which actions should need your approval

Model providers and your content

Running an agent means sending its context to a language model, and some tools send part of a request to a specialised service. This is where it goes.

  • Agents run on a model deployment in our own Azure AI Foundry resource (Azure OpenAI). It uses Azure’s Global Standard deployment type, so a request may be processed in any Azure region, even though your stored data stays in Central India.
  • Every run uses this platform model. Choosing a different model or bringing your own API key is not supported.
  • When an agent calls certain tools, that tool’s input goes to its provider: Replicate for image and video generation, Exa for web search. The full list is in our Privacy Policy.
  • We do not train models on your data.

What we log

Enough to run the service, debug it, and show you what your agents did.

  • Each run records which tools were called and how many tokens it used, so you can see what your agents did.
  • Prompts and model responses are sent to Langfuse, an LLM tracing service, so we can investigate failed or poor runs.
  • Operational logs capture errors and metrics for reliability work. Known secret fields are scrubbed before anything is written.
  • The site uses Google Analytics and Microsoft Clarity, which records session replays, to understand how it is used.

Retention and deletion

Your data stays until you remove it or ask us to.

  • Deleting an agent removes its configuration, its memories and its grants.
  • Disconnecting an integration deletes the stored tokens for it.
  • There is no self-serve account deletion yet. Email privacy@selfagentic.in and we will delete your account and the data attached to it within 30 days.

What we don’t claim yet

Certifications get claimed loosely in this category. Here is where we actually stand.

  • We are not SOC 2 or ISO 27001 certified, and will not claim otherwise.
  • We have not completed a third-party penetration test.
  • There is no SSO/SAML, no team or organisation accounts, and no role-based access control. Each account belongs to one person.

Questions, or a security report?

Email us at privacy@selfagentic.in. Review our Privacy Policy and Terms for the legal detail.

Contact us