Trust Center

Security & Trust

AgentPMO is built for regulated enterprises. Here is exactly how we protect your data, who can access it, and where it lives.

Security controls

Twelve technical controls are built into the platform. All are active in production today.

Encryption at rest & in transit

All data is encrypted at rest using AES-256 (Neon Postgres). All connections enforce TLS 1.2+. No plaintext data leaves the platform.

Multi-factor authentication

MFA is enforced via Clerk for all user accounts. Org admins can mandate MFA for every team member.

Role-based access control

Three-tier RBAC (Admin / Reviewer / Viewer) is enforced at both the API and UI layers. Least-privilege by default.

Immutable audit logging

Every create, update, and delete is captured in an append-only audit_events table with actor identity, before/after JSON, and IP address.

API key hashing

API keys are hashed with bcrypt before storage. The raw key is shown once at creation and never stored. Prefix-based identification only.

HMAC-signed webhooks

All outbound webhook deliveries include an X-AgentPMO-Signature: sha256=<hex> header so consumers can verify payload authenticity.

Rate limiting

Token-bucket rate limiting is applied per API key and endpoint tier. Limits are surfaced in X-RateLimit-* response headers.

Dependency & vulnerability scanning

npm audit and Snyk run on every CI build. Critical CVEs block deployment. High-severity CVEs are patched within 72 hours.

Error monitoring

Sentry captures client and server exceptions in real time. Every error carries a request ID for full-stack correlation.

Secrets management

All secrets are stored as environment variables, never in source code. Production secrets rotate on a 90-day cycle.

Incident response plan

Documented P1–P4 severity classification, escalation paths, and customer communication playbook. P1 RTO < 4 hours.

Continuous backups

Neon Postgres provides continuous WAL streaming plus daily snapshots. 7-day point-in-time recovery. RPO < 1 hour.

Certifications & frameworks

Our certification roadmap is public. We engage Vanta for automated SOC 2 evidence collection.

SOC 2 Type II
In progress

Engaging Vanta for automated evidence collection. Audit window opens Q2 2026.

ISO 27001
Planned

Information security management system aligned with ISO 27001 controls.

GDPR
Compliant

EU-region deployment available. Data processing agreement available on request.

EU AI Act
Built-in

AgentPMO is built specifically to help you comply β€” risk classification, evidence packages, and conformity readiness.

Data residency

Choose your data region at organization setup. GDPR-regulated buyers in the EU can select EU (Frankfurt) to ensure data never leaves the European Union.

πŸ‡ΊπŸ‡Έ
United States
Neon Postgres Β· AWS us-east-1 (Virginia)
Default

Default region for all new organizations. Data never leaves AWS us-east-1.

πŸ‡ͺπŸ‡Ί
European Union
Neon Postgres Β· AWS eu-central-1 (Frankfurt)
GDPR

EU-region deployment for regulated buyers. All data stored and processed within the EU. Select EU at organization setup or contact sales.

Note: Data region is set at organization creation and cannot be self-serve changed after provisioning. Contact support@getagentpmo.com for a migration request.

Availability & recovery

99.9%
Uptime SLA
Monthly SLA commitment
< 4h
P1 RTO
Recovery time objective
< 1h
RPO
Recovery point objective
7 days
Backup retention
Point-in-time recovery

Vulnerability management

SeveritySLA to patchDisclosure
Critical24 hoursPublic after patch
High72 hoursPublic after patch
Medium14 daysNext release cycle
Low30 daysNext release cycle

To report a vulnerability, email security@getagentpmo.com. We acknowledge disclosures within 24 hours and follow responsible disclosure principles.

SOC 2 Type II β€” in progress

We have engaged Vanta for automated SOC 2 evidence collection. The audit window opens Q2 2026 with a target report date of Q3 2026. Controls already in place: access logging, encryption, MFA enforcement, RBAC, and incident response.

Access logging βœ“Encryption at rest βœ“MFA enforcement βœ“RBAC βœ“Audit trail βœ“Incident response plan βœ“Pen test β€” Q1 2026Auditor engagement β€” Q2 2026

Enterprise customers can request a copy of the SOC 2 report on completion. Contact trust@getagentpmo.com.

Security disclosures
security@getagentpmo.com

Vulnerability reports, penetration test findings, and security questions.

Trust center & audit reports
trust@getagentpmo.com

SOC 2 reports (when available), DPAs, and enterprise compliance documentation.