Security
Your clients’ data, and what we do not do with it.
Your client data is processed under zero-retention terms and is never used to train any model. Nothing is written back to your PSA until one of your engineers approves it. Our SOC 1 Type 2 and SOC 2 Type 2 examinations are both complete, and the reports are available under NDA.
This page is written so you can forward it to your own clients under your own cover note. Your clients are asking you these questions, and you should not have to write the answers yourself.
Independent audit
SOC 1 & 2
Type 2. Both complete.
A Type 2 report examines whether controls actually operated over a period of time, rather than whether they existed on the day somebody looked. That is the one your clients’ auditors are asking you about. SOC 2 covers security, availability and confidentiality; SOC 1 covers administrative controls and back-office operations, which is the one an enterprise client’s finance function asks for and most vendors your size do not have.
The reports themselves go to customers, under NDA, and to the auditors who audit those customers. That is what the restricted-use legend on a SOC report allows, and it is the same on everybody’s. This page is the part written to be forwarded, to a client or to their auditor, under your own cover note.
If you are filling in a client security questionnaire and need a specific control answered, ask and we will answer it directly rather than pointing you at a portal.
The model layer
Named providers, zero retention, no training.
Most vendors will not tell you whose models they run. We will, because the answer is part of the diligence and because you are going to be asked it by your own clients.
Anthropic
Claude, for ticket analysis and Ask AI. The reasoning and the search.
OpenAI
Alongside Anthropic across the platform.
Groq
Voice transcription, which is why the call is written up in seconds rather than minutes.
What we do
- Use enterprise API endpoints under zero-retention terms
- Send only what is needed to answer the question in front of the engineer
- Keep every customer's data separated from every other customer's
- Record what was asked, what was done, and who approved it
What we do not do
- Train any model on your data, or your clients' data
- Allow a provider to retain your prompts or your content
- Let one customer's data inform another customer's answers
- Write to your PSA without a person approving it
Access
Scoped to what it needs, granted by you, revocable by you.
Access is established during onboarding through API members you create inside your own systems, permissioned to exactly what the agent reads and writes. You grant it, you can see it in your own audit trail, and you can revoke it at any time without asking us. We never hold an interactive login to your environment, and we never ask for one.
What it reads
- Your PSA
- ConnectWise Manage, Autotask, HaloPSA or ServiceNow. Tickets, time entries, agreements, companies and contacts.
- Your documentation
- IT Glue, Hudu, SharePoint or Confluence. The pages your engineers already rely on.
- Your asset data
- ScalePad Lifecycle Manager, where you have it, for hardware age and lifecycle.
- Microsoft 365
- For Agent-X only, and only for the actions you have enabled per client.
What it writes, and when
- Ticket notes and time entries
- When an engineer reviews the draft and posts it. Never before.
- Ticket subject, type, subtype and priority
- Suggested to the engineer, applied when they accept it.
- Documentation drafts
- Into IT Glue or Hudu in draft status, for a human to review and publish.
- Tracking and opportunity tickets
- Into your PSA, assigned to a person, so nothing lands silently.
Call recordings are attached to the ticket in your PSA, inside your tenancy, so the record of what was promised lives where your engineers already look for it.
Agent-X
When an agent can act, the limits matter more than the abilities.
Agent-X performs actions in Microsoft 365 on behalf of a client’s staff, which is the part of the platform that deserves the hardest questions. These limits are built into the product rather than configured per customer, so they cannot be switched off by accident.
- Administrator accounts are refused outright, and the check fails closed.
- An account disabled in Microsoft 365 cannot self-recover, checked at the moment of the action rather than at sign-in.
- A request cannot name an account. Agent-X acts on the person making it, never on a colleague.
- A temporary password is never written into the ticket or the chat record. Your engineers do not see it either.
- Every action is recorded with who asked, who approved, and what was done.
And you choose how much it does unattended.
Every tool Agent-X has belongs to one of twelve groups, and every group sits at one of six positions. You set them once for your MSP and override them per client, so the policy is twelve answers rather than a matrix nobody maintains. The twelve groups, and where each ships.
Automatic
The agent does it, and records that it did.
The user confirms
The person at the keyboard approves first.
Ask the resource owner
Routed to whoever owns that Team, list or site in Entra.
Ask an engineer
Held for your service desk, in the queue they already work.
Off
Not offered at all. The agent will not mention it.
Not governed
Conversation mechanics. Blocking these breaks the chat rather than securing it.
Two of the twelve ship off, including anything capable of unbounded execution: a shell, or a runbook that can name any operation. Those cannot be reasoned about in advance, so they stay off unless you deliberately turn them on. What a tool is advertised as being able to do never overrides the position you set for that client.
The same idea appears in Scheduler, where a confidence threshold decides what is assigned without being asked. It is deliberate: the customer decides how much the machine does on its own.
For your clients
The questions arrive at your desk, not ours.
Agent-X can be branded to your MSP, and you are the one holding the client relationship either way. That is the right outcome commercially, and it means the security questions land with you.
So this page is built to be forwarded, and if a client sends you a questionnaire we will help you answer it. We would rather spend an hour on your response than have you guess at ours.
Bring your hardest question.
If you run technical diligence for your MSP, the fastest path is a call with the people who built it rather than a form. Nothing on this page is something we will not put in writing.
