SOC 2 Type 1
Readiness underway; the audit will be scheduled once budget allows.
ACP is an early-stage product run by a small team. This page lists what is in place today, what we are building now, and what we do not have yet, so you can make an informed decision. Every implemented control maps to code we can walk you through.
ACP is a control plane for AI agents you already run. Your agents call their model providers directly; ACP receives the telemetry your SDK reports and can send signed, scoped commands back. New connections are monitor-only until you enable more.
We protect that data with tenant isolation on every query, hashed API keys, signed commands, encrypted webhook secrets, strict security headers, and automatic deletion of run records. Our optional AI features send run content to the AI providers listed under Subprocessors; we say so plainly because it matters for your review.
We have not completed a SOC 2 audit or an independent penetration test. Both are on the roadmap below.
43 controls tracked
Each control is marked Implemented (live in production today), In progress (being built now), or Planned (on the roadmap, not started).
How the platform, its database, and its web surface are configured and protected.
Row-level security is enabled and default grants are revoked for the database’s public API roles, so data is reachable only through the ACP server.
Content Security Policy that only allows our own scripts, HSTS, frame protection, and MIME-sniffing protection.
API responses carry no-store caching headers so browsers and intermediaries do not keep copies.
The server refuses to start in production with a weak or missing session secret, a shared-password login left enabled, or no encryption key for stored secrets.
Sign-in and password storage are handled by Supabase Auth; ACP never stores user passwords itself.
The server refuses to start in production unless its database connection uses TLS. Certificate verification against a pinned CA is supported and recommended.
External uptime checks with a public status page and incident history.
A documented, periodically exercised restore of the production database from backup.
An option to host an organization’s data in the European Union. Today all data is hosted in the United States.
Policies, people, and independent assurance.
Information security, access control, incident response, vendor management, and data retention policies.
Readiness work is underway; the independent audit will be scheduled once budget allows.
Follows the Type 1 report and an observation period.
A third-party assessment of the application and API, with a summary available to customers.
Formal onboarding and annual security training for everyone with production access.
Background checks for personnel with access to production systems, where lawful.
Monetary rewards for qualifying reports. Today we run a responsible disclosure program with public credit.
Security built into how ACP authenticates, authorizes, and controls agents.
Every read and write is scoped to the caller’s organization, with automated tests that try to cross organization boundaries.
API keys are stored only as SHA-256 hashes and can be scoped, given an expiry, and revoked at any time.
Commands sent to your agents are signed with HMAC-SHA256 over a timestamp and a single-use nonce, so they cannot be forged or replayed.
New connections can only report. Prompt edits and Test Lab results require explicit approval by an organization owner or admin, against the exact version they were proposed on, and expire after 7 days. Editing a shared skill applies to its assigned agents immediately: that is limited to owners and admins on apps with full control, versioned with one-click rollback, and recorded in the audit log.
Key, secret, scope, and settings changes require the owner or admin role; denied attempts are audited.
Customer webhook URLs are validated so ACP cannot be pointed at private or internal network addresses.
Sign-in, ingest, prompt, and AI endpoints are rate limited, with a daily AI quota per organization.
Run content sent to AI features is fenced and marked as untrusted data to reduce prompt-injection risk.
ACP’s own AI features only call allow-listed models, with input-size limits and per-organization usage caps.
Operators with platform-admin access must sign in with a verified second factor (TOTP) before the admin console will respond. Organization owners can also require MFA for individual members.
Single sign-on through your identity provider, with enforced sign-in policies.
How we build, review, log, and respond.
Changes to API keys, webhook secrets, control scopes, commands, settings, and skills are recorded with actor and time.
Database triggers reject edits and deletions of audit entries; only the documented retention sweep may remove entries older than 365 days. Operator actions go to a separate append-only log.
A platform admin console where every operator action is written to an append-only audit log before it runs, and also appears in the affected organization’s own audit trail.
Every change runs a dependency vulnerability audit; CI actions are pinned to commits and run with a least-privilege token.
A pre-commit hook blocks credentials, keys, and connection strings from entering the repository.
Dependabot updates, CodeQL static analysis, and repository secret scanning.
Request bodies are never written to logs, and internal error details are never returned to clients.
A standard /.well-known/security.txt points researchers to our contact and responsible disclosure policy.
How customer data is protected, retained, exported, and deleted.
Webhook signing secrets are encrypted in the application with AES-256-GCM, with support for key rotation.
Run records are deleted automatically once they are older than the organization’s retention window (30 days on Free and Hobby, 90 days on Team).
Automatic deletion covers every telemetry table on the organization’s retention window, audit logs after 365 days, and early-access applications after 24 months.
Self-service export of all organization data and full deletion, available to organization owners.
Delete individual runs so you can honor an end user’s erasure request without deleting anything else.
Owners choose whether ACP’s AI features are enabled, limited to the primary provider (no fallback), or disabled.
The site and dashboard use only strictly necessary cookies and storage; the Content Security Policy blocks third-party scripts.
The dashboard and marketing site self-host their fonts, so loading them makes no requests to third-party servers.
Where we stand on common frameworks. We will update this page as each step happens.
Readiness underway; the audit will be scheduled once budget allows.
Follows Type 1 and an observation period.
Data Processing Addendum, subprocessor list, and data-rights tooling. GDPR has no certification; this describes our program, not an attestation.
Not currently planned; we will revisit after SOC 2.
If any of these is a requirement for you, tell us. It helps us decide what to build next.
Third parties that process data on our behalf. Those that handle customer data are Subprocessors under the DPA (Annex III); the rows marked “no customer data” are listed for transparency. We will give notice of changes as described in the Data Processing Addendum. If you configure an alert webhook (for example, to Discord), that destination is chosen by you and is not our subprocessor.
| Subprocessor | Purpose | Data involved | Location |
|---|---|---|---|
| Supabase | Postgres database and user authentication | All account and customer data | United States (AWS us-east-1) |
| Railway | Application hosting and application logs | All data in transit and during processing | United States |
| Anthropic | Primary model for ACP’s AI features (quality reviews, error explanations, Test Lab judging, integration analysis and code generation); customer agents that run on Claude models | Run content selected for an AI feature | United States |
| OpenAI | Fallback model for the same AI features; customer agents that run on GPT models | Run content selected for an AI feature | United States |
| Google (Gemini) | Fallback model for the same AI features; customer agents that run on Gemini models | Run content selected for an AI feature | United States |
| xAI | Customer agents that run on Grok models; model-pricing lookups | Run content for Grok-based agents; pricing lookups send model names only | United States |
| Perplexity | Customer agents that run on Sonar models | Run content for Sonar-based agents | United States |
| OpenRouter | Routing to a model provider when a direct provider is unavailable; model-pricing catalog | Run content when routed; pricing lookups send model names only | United States |
| GitHub | Source code hosting and continuous integration | No customer data | United States |
| Resend | Delivery of sign-in, confirmation and password-reset emails sent by our authentication provider | Account email addresses and the content of those emails; no customer data | United States |
| Cloudflare | Network in front of the Service: TLS, DDoS and bot protection, caching of public files, DNS; sign-in protection for ACP’s internal operator console | All data in transit (it is not stored, apart from cached public files and security logs) | Global network (edge location nearest the user) |
AI features are optional. Organization owners can switch ACP’s AI processing to “no fallback” (Anthropic only) or turn it off in settings.
All customer data is stored and processed in the United States. The database runs on Supabase in AWS us-east-1; the application runs on Railway. Requests pass through Cloudflare’s network, which decrypts and re-encrypts them at the edge location nearest the user to block attacks; it does not store customer data.
Traffic between your browser or SDK and ACP uses HTTPS, and HSTS tells browsers to use it for all future visits. Webhook signing secrets are additionally encrypted by ACP with AES-256-GCM. API keys are stored only as hashes. Storage encryption for the database is provider-managed.
Run records are deleted automatically after your organization’s retention window (30 days on Free and Hobby, 90 days on Team). Ingest attempt logs are kept for 7 days. Audit logs are kept for 365 days and early-access applications for up to 24 months, and are then deleted automatically. Details are in the Privacy Policy.
ACP never sits between your agent and its model: your agent calls its provider directly with your keys. Separately, ACP’s own optional AI features (quality reviews, error explanations, Test Lab judging, integration analysis) send the relevant run content, such as prompts, outputs, and errors, to Anthropic, with OpenAI and Google as fallbacks. Organization owners can limit this to the primary provider or turn it off in settings.
You choose what your agents report. Organization owners can export or delete all organization data from the dashboard and can delete individual runs. You can always email us and we will do it for you.
Contract templates and security answers are shared with companies evaluating ACP. Tell us who you are; we review every request and send a private link that works for 30 days.
Found a vulnerability? Email Founders@skaigroup.tech with steps to reproduce. We acknowledge reports within 3 business days, will not pursue good-faith research that follows our policy, and credit researchers in our Hall of Fame. Paid rewards are planned once budget allows.
Read the Responsible Disclosure policy · Machine-readable contact: /.well-known/security.txt
Not yet. SOC 2 is an independent audit report, and we have not been audited. Type 1 readiness work is underway and the audit will be scheduled once budget allows. Our infrastructure providers maintain their own SOC 2 reports, but those cover their services, not ACP.
No. Your agent calls its model provider directly. ACP receives the telemetry your SDK reports, and sends signed commands to your agent only for the scopes you enable.
Only when you use ACP’s AI features, such as quality reviews, error explanations, or Test Lab judging. Those features send the relevant run content to Anthropic, with OpenAI or Google as a fallback. They are listed as subprocessors above.
In the United States. We do not offer EU or UK data residency yet.
Run records are deleted after your organization’s retention window: 30 days on Free and Hobby, 90 days on Team. Other retention periods are listed in the Privacy Policy.
Yes. Our Data Processing Addendum is published and forms part of the Terms. If you need a countersigned copy, email us.
Yes. Email the founders and we will answer it directly and honestly, including where the answer is “not yet”.
Follow the Responsible Disclosure policy and email the security contact. We acknowledge reports within 3 business days.