xop.ai

Security

Your clients’ data, and what we do not do with it.

Your client data is processed under zero-retention terms and is never used to train any model. Nothing is written back to your PSA until one of your engineers approves it. Our SOC 1 Type 2 and SOC 2 Type 2 examinations are both complete, and the reports are available under NDA.

This page is written so you can forward it to your own clients under your own cover note. Your clients are asking you these questions, and you should not have to write the answers yourself.

Independent audit

SOC 1 & 2

Type 2. Both complete.

A Type 2 report examines whether controls actually operated over a period of time, rather than whether they existed on the day somebody looked. That is the one your clients’ auditors are asking you about. SOC 2 covers security, availability and confidentiality; SOC 1 covers administrative controls and back-office operations, which is the one an enterprise client’s finance function asks for and most vendors your size do not have.

The reports themselves go to customers, under NDA, and to the auditors who audit those customers. That is what the restricted-use legend on a SOC report allows, and it is the same on everybody’s. This page is the part written to be forwarded, to a client or to their auditor, under your own cover note.

If you are filling in a client security questionnaire and need a specific control answered, ask and we will answer it directly rather than pointing you at a portal.

partner@xop.ai

The model layer

Named providers, zero retention, no training.

Most vendors will not tell you whose models they run. We will, because the answer is part of the diligence and because you are going to be asked it by your own clients.

Anthropic

Claude, for ticket analysis and Ask AI. The reasoning and the search.

OpenAI

Alongside Anthropic across the platform.

Groq

Voice transcription, which is why the call is written up in seconds rather than minutes.

What we do

  • Use enterprise API endpoints under zero-retention terms
  • Send only what is needed to answer the question in front of the engineer
  • Keep every customer's data separated from every other customer's
  • Record what was asked, what was done, and who approved it

What we do not do

  • Train any model on your data, or your clients' data
  • Allow a provider to retain your prompts or your content
  • Let one customer's data inform another customer's answers
  • Write to your PSA without a person approving it

Access

Scoped to what it needs, granted by you, revocable by you.

Access is established during onboarding through API members you create inside your own systems, permissioned to exactly what the agent reads and writes. You grant it, you can see it in your own audit trail, and you can revoke it at any time without asking us. We never hold an interactive login to your environment, and we never ask for one.

What it reads

Your PSA
ConnectWise Manage, Autotask, HaloPSA or ServiceNow. Tickets, time entries, agreements, companies and contacts.
Your documentation
IT Glue, Hudu, SharePoint or Confluence. The pages your engineers already rely on.
Your asset data
ScalePad Lifecycle Manager, where you have it, for hardware age and lifecycle.
Microsoft 365
For Agent-X only, and only for the actions you have enabled per client.

What it writes, and when

Ticket notes and time entries
When an engineer reviews the draft and posts it. Never before.
Ticket subject, type, subtype and priority
Suggested to the engineer, applied when they accept it.
Documentation drafts
Into IT Glue or Hudu in draft status, for a human to review and publish.
Tracking and opportunity tickets
Into your PSA, assigned to a person, so nothing lands silently.

Call recordings are attached to the ticket in your PSA, inside your tenancy, so the record of what was promised lives where your engineers already look for it.

Agent-X

When an agent can act, the limits matter more than the abilities.

Agent-X performs actions in Microsoft 365 on behalf of a client’s staff, which is the part of the platform that deserves the hardest questions. These limits are built into the product rather than configured per customer, so they cannot be switched off by accident.

And you choose how much it does unattended.

Every tool Agent-X has belongs to one of twelve groups, and every group sits at one of six positions. You set them once for your MSP and override them per client, so the policy is twelve answers rather than a matrix nobody maintains. The twelve groups, and where each ships.

01

Automatic

The agent does it, and records that it did.

02

The user confirms

The person at the keyboard approves first.

03

Ask the resource owner

Routed to whoever owns that Team, list or site in Entra.

04

Ask an engineer

Held for your service desk, in the queue they already work.

05

Off

Not offered at all. The agent will not mention it.

06

Not governed

Conversation mechanics. Blocking these breaks the chat rather than securing it.

Two of the twelve ship off, including anything capable of unbounded execution: a shell, or a runbook that can name any operation. Those cannot be reasoned about in advance, so they stay off unless you deliberately turn them on. What a tool is advertised as being able to do never overrides the position you set for that client.

The same idea appears in Scheduler, where a confidence threshold decides what is assigned without being asked. It is deliberate: the customer decides how much the machine does on its own.

For your clients

The questions arrive at your desk, not ours.

Agent-X can be branded to your MSP, and you are the one holding the client relationship either way. That is the right outcome commercially, and it means the security questions land with you.

So this page is built to be forwarded, and if a client sends you a questionnaire we will help you answer it. We would rather spend an hour on your response than have you guess at ours.

Bring your hardest question.

If you run technical diligence for your MSP, the fastest path is a call with the people who built it rather than a form. Nothing on this page is something we will not put in writing.