Security & Trust

How we protect your agents and your data.

ACP is an early-stage product run by a small team. This page lists what is in place today, what we are building now, and what we do not have yet, so you can make an informed decision. Every implemented control maps to code we can walk you through.

Last reviewed:

Overview

ACP is a control plane for AI agents you already run. Your agents call their model providers directly; ACP receives the telemetry your SDK reports and can send signed, scoped commands back. New connections are monitor-only until you enable more.

We protect that data with tenant isolation on every query, hashed API keys, signed commands, encrypted webhook secrets, strict security headers, and automatic deletion of run records. Our optional AI features send run content to the AI providers listed under Subprocessors; we say so plainly because it matters for your review.

We have not completed a SOC 2 audit or an independent penetration test. Both are on the roadmap below.

Security level

43 controls tracked

Implemented
33
In progress
0
Planned
10
Security contact Founders@skaigroup.tech Vulnerability reports: see Responsible Disclosure.

Controls

Each control is marked Implemented (live in production today), In progress (being built now), or Planned (on the roadmap, not started).

Infrastructure security

How the platform, its database, and its web surface are configured and protected.

  • Database public roles locked down

    Row-level security is enabled and default grants are revoked for the database’s public API roles, so data is reachable only through the ACP server.

    Implemented
  • Security headers on every page

    Content Security Policy that only allows our own scripts, HSTS, frame protection, and MIME-sniffing protection.

    Implemented
  • API responses are never cached

    API responses carry no-store caching headers so browsers and intermediaries do not keep copies.

    Implemented
  • Secure-configuration boot guards

    The server refuses to start in production with a weak or missing session secret, a shared-password login left enabled, or no encryption key for stored secrets.

    Implemented
  • Passwords handled by a managed identity provider

    Sign-in and password storage are handled by Supabase Auth; ACP never stores user passwords itself.

    Implemented
  • Encrypted database connections enforced

    The server refuses to start in production unless its database connection uses TLS. Certificate verification against a pinned CA is supported and recommended.

    Implemented
  • Public status page and uptime monitoring

    External uptime checks with a public status page and incident history.

    Planned
  • Formal disaster-recovery test

    A documented, periodically exercised restore of the production database from backup.

    Planned
  • EU data residency option

    An option to host an organization’s data in the European Union. Today all data is hosted in the United States.

    Planned

Organizational security

Policies, people, and independent assurance.

  • Written security and compliance policies

    Information security, access control, incident response, vendor management, and data retention policies.

    Implemented
  • SOC 2 Type 1 audit

    Readiness work is underway; the independent audit will be scheduled once budget allows.

    Planned
  • SOC 2 Type 2 audit

    Follows the Type 1 report and an observation period.

    Planned
  • Independent penetration test

    A third-party assessment of the application and API, with a summary available to customers.

    Planned
  • Security awareness training program

    Formal onboarding and annual security training for everyone with production access.

    Planned
  • Background checks

    Background checks for personnel with access to production systems, where lawful.

    Planned
  • Paid bug bounty

    Monetary rewards for qualifying reports. Today we run a responsible disclosure program with public credit.

    Planned

Product security

Security built into how ACP authenticates, authorizes, and controls agents.

  • Tenant isolation on every query

    Every read and write is scoped to the caller’s organization, with automated tests that try to cross organization boundaries.

    Implemented
  • Hashed, scoped API keys

    API keys are stored only as SHA-256 hashes and can be scoped, given an expiry, and revoked at any time.

    Implemented
  • Signed control commands

    Commands sent to your agents are signed with HMAC-SHA256 over a timestamp and a single-use nonce, so they cannot be forged or replayed.

    Implemented
  • Monitor-only by default

    New connections can only report. Prompt edits and Test Lab results require explicit approval by an organization owner or admin, against the exact version they were proposed on, and expire after 7 days. Editing a shared skill applies to its assigned agents immediately: that is limited to owners and admins on apps with full control, versioned with one-click rollback, and recorded in the audit log.

    Implemented
  • Role-based access for sensitive actions

    Key, secret, scope, and settings changes require the owner or admin role; denied attempts are audited.

    Implemented
  • Outbound request (SSRF) protection

    Customer webhook URLs are validated so ACP cannot be pointed at private or internal network addresses.

    Implemented
  • Rate limiting and per-organization AI quotas

    Sign-in, ingest, prompt, and AI endpoints are rate limited, with a daily AI quota per organization.

    Implemented
  • Untrusted-data isolation in AI prompts

    Run content sent to AI features is fenced and marked as untrusted data to reduce prompt-injection risk.

    Implemented
  • AI model allowlist and usage caps

    ACP’s own AI features only call allow-listed models, with input-size limits and per-organization usage caps.

    Implemented
  • MFA for platform administrators

    Operators with platform-admin access must sign in with a verified second factor (TOTP) before the admin console will respond. Organization owners can also require MFA for individual members.

    Implemented
  • SSO / SAML

    Single sign-on through your identity provider, with enforced sign-in policies.

    Planned

Internal security procedures

How we build, review, log, and respond.

  • Security audit trail

    Changes to API keys, webhook secrets, control scopes, commands, settings, and skills are recorded with actor and time.

    Implemented
  • Tamper-resistant audit log

    Database triggers reject edits and deletions of audit entries; only the documented retention sweep may remove entries older than 365 days. Operator actions go to a separate append-only log.

    Implemented
  • Audited operator console

    A platform admin console where every operator action is written to an append-only audit log before it runs, and also appears in the affected organization’s own audit trail.

    Implemented
  • Dependency scanning and hardened CI

    Every change runs a dependency vulnerability audit; CI actions are pinned to commits and run with a least-privilege token.

    Implemented
  • Pre-commit secret scanning

    A pre-commit hook blocks credentials, keys, and connection strings from entering the repository.

    Implemented
  • Automated dependency updates and code scanning

    Dependabot updates, CodeQL static analysis, and repository secret scanning.

    Implemented
  • No request bodies in logs, no internal errors exposed

    Request bodies are never written to logs, and internal error details are never returned to clients.

    Implemented
  • security.txt and disclosure policy

    A standard /.well-known/security.txt points researchers to our contact and responsible disclosure policy.

    Implemented

Data & privacy

How customer data is protected, retained, exported, and deleted.

  • Webhook secrets encrypted at rest

    Webhook signing secrets are encrypted in the application with AES-256-GCM, with support for key rotation.

    Implemented
  • Automatic deletion of run records

    Run records are deleted automatically once they are older than the organization’s retention window (30 days on Free and Hobby, 90 days on Team).

    Implemented
  • Retention for all telemetry and logs

    Automatic deletion covers every telemetry table on the organization’s retention window, audit logs after 365 days, and early-access applications after 24 months.

    Implemented
  • Organization data export and deletion

    Self-service export of all organization data and full deletion, available to organization owners.

    Implemented
  • Per-run deletion for erasure requests

    Delete individual runs so you can honor an end user’s erasure request without deleting anything else.

    Implemented
  • AI processing controls per organization

    Owners choose whether ACP’s AI features are enabled, limited to the primary provider (no fallback), or disabled.

    Implemented
  • No advertising or analytics cookies

    The site and dashboard use only strictly necessary cookies and storage; the Content Security Policy blocks third-party scripts.

    Implemented
  • No third-party requests from the dashboard

    The dashboard and marketing site self-host their fonts, so loading them makes no requests to third-party servers.

    Implemented

Compliance roadmap

Where we stand on common frameworks. We will update this page as each step happens.

Planned

SOC 2 Type 1

Readiness underway; the audit will be scheduled once budget allows.

Planned

SOC 2 Type 2

Follows Type 1 and an observation period.

Program in place

GDPR

Data Processing Addendum, subprocessor list, and data-rights tooling. GDPR has no certification; this describes our program, not an attestation.

Future

ISO/IEC 27001

Not currently planned; we will revisit after SOC 2.

What we don’t have yet

If any of these is a requirement for you, tell us. It helps us decide what to build next.

  • A SOC 2 report of any type. No audit has started.
  • An independent penetration test.
  • SSO / SAML, or an organization-wide policy that forces every member to use multi-factor authentication. Members can enable MFA themselves today.
  • A public status page, an uptime SLA, or round-the-clock on-call monitoring.
  • A tested disaster-recovery plan. We have not tested a restore from backup; any backups are provider-managed.
  • Application-level encryption of all customer data. Only webhook secrets and alert webhook URLs are encrypted by ACP; other data relies on our database provider’s storage encryption.
  • EU or UK data residency. All data is hosted in the United States.
  • A paid bug bounty.
  • A security team. ACP is built and operated by a very small team; security questions go directly to the founders.

Subprocessors

Third parties that process data on our behalf. Those that handle customer data are Subprocessors under the DPA (Annex III); the rows marked “no customer data” are listed for transparency. We will give notice of changes as described in the Data Processing Addendum. If you configure an alert webhook (for example, to Discord), that destination is chosen by you and is not our subprocessor.

SubprocessorPurposeData involvedLocation
SupabasePostgres database and user authenticationAll account and customer dataUnited States (AWS us-east-1)
RailwayApplication hosting and application logsAll data in transit and during processingUnited States
AnthropicPrimary model for ACP’s AI features (quality reviews, error explanations, Test Lab judging, integration analysis and code generation); customer agents that run on Claude modelsRun content selected for an AI featureUnited States
OpenAIFallback model for the same AI features; customer agents that run on GPT modelsRun content selected for an AI featureUnited States
Google (Gemini)Fallback model for the same AI features; customer agents that run on Gemini modelsRun content selected for an AI featureUnited States
xAICustomer agents that run on Grok models; model-pricing lookupsRun content for Grok-based agents; pricing lookups send model names onlyUnited States
PerplexityCustomer agents that run on Sonar modelsRun content for Sonar-based agentsUnited States
OpenRouterRouting to a model provider when a direct provider is unavailable; model-pricing catalogRun content when routed; pricing lookups send model names onlyUnited States
GitHubSource code hosting and continuous integrationNo customer dataUnited States
ResendDelivery of sign-in, confirmation and password-reset emails sent by our authentication providerAccount email addresses and the content of those emails; no customer dataUnited States
CloudflareNetwork in front of the Service: TLS, DDoS and bot protection, caching of public files, DNS; sign-in protection for ACP’s internal operator consoleAll data in transit (it is not stored, apart from cached public files and security logs)Global network (edge location nearest the user)

AI features are optional. Organization owners can switch ACP’s AI processing to “no fallback” (Anthropic only) or turn it off in settings.

Data handling

Hosting location

All customer data is stored and processed in the United States. The database runs on Supabase in AWS us-east-1; the application runs on Railway. Requests pass through Cloudflare’s network, which decrypts and re-encrypts them at the edge location nearest the user to block attacks; it does not store customer data.

Encryption

Traffic between your browser or SDK and ACP uses HTTPS, and HSTS tells browsers to use it for all future visits. Webhook signing secrets are additionally encrypted by ACP with AES-256-GCM. API keys are stored only as hashes. Storage encryption for the database is provider-managed.

Retention

Run records are deleted automatically after your organization’s retention window (30 days on Free and Hobby, 90 days on Team). Ingest attempt logs are kept for 7 days. Audit logs are kept for 365 days and early-access applications for up to 24 months, and are then deleted automatically. Details are in the Privacy Policy.

AI features and providers

ACP never sits between your agent and its model: your agent calls its provider directly with your keys. Separately, ACP’s own optional AI features (quality reviews, error explanations, Test Lab judging, integration analysis) send the relevant run content, such as prompts, outputs, and errors, to Anthropic, with OpenAI and Google as fallbacks. Organization owners can limit this to the primary provider or turn it off in settings.

Your control

You choose what your agents report. Organization owners can export or delete all organization data from the dashboard and can delete individual runs. You can always email us and we will do it for you.

Documents

Request documents

Contract templates and security answers are shared with companies evaluating ACP. Tell us who you are; we review every request and send a private link that works for 30 days.

Documents

We use these details only to answer this request and delete them after 24 months. See the Privacy Policy.

Responsible disclosure

Found a vulnerability? Email Founders@skaigroup.tech with steps to reproduce. We acknowledge reports within 3 business days, will not pursue good-faith research that follows our policy, and credit researchers in our Hall of Fame. Paid rewards are planned once budget allows.

Read the Responsible Disclosure policy · Machine-readable contact: /.well-known/security.txt

Frequently asked questions

Do you have a SOC 2 report?

Not yet. SOC 2 is an independent audit report, and we have not been audited. Type 1 readiness work is underway and the audit will be scheduled once budget allows. Our infrastructure providers maintain their own SOC 2 reports, but those cover their services, not ACP.

Does ACP see my model provider API keys or sit in the model call path?

No. Your agent calls its model provider directly. ACP receives the telemetry your SDK reports, and sends signed commands to your agent only for the scopes you enable.

Is my run data sent to AI providers?

Only when you use ACP’s AI features, such as quality reviews, error explanations, or Test Lab judging. Those features send the relevant run content to Anthropic, with OpenAI or Google as a fallback. They are listed as subprocessors above.

Where is my data stored?

In the United States. We do not offer EU or UK data residency yet.

How long do you keep run data?

Run records are deleted after your organization’s retention window: 30 days on Free and Hobby, 90 days on Team. Other retention periods are listed in the Privacy Policy.

Can I get a DPA signed?

Yes. Our Data Processing Addendum is published and forms part of the Terms. If you need a countersigned copy, email us.

Can I fill out our security questionnaire?

Yes. Email the founders and we will answer it directly and honestly, including where the answer is “not yet”.

How do I report a vulnerability?

Follow the Responsible Disclosure policy and email the security contact. We acknowledge reports within 3 business days.