Agenthub

Security is the product.

Agenthub exists so companies can hand real work to agents without losing control. That promise starts below the features: where your data lives, who can touch it, and what happens when you leave.

Certified & compliant.

We operate from the EU, under EU law, and are working with independent auditors to certify what we already practice.

operating basis

GDPR

Built and operated under GDPR from day one: EU establishment, EU hosting, data-processing agreements, and documented subprocessors.

in progress

SOC 2 Type II

Controls are implemented and the audit process is underway. Ask us for current status and our security documentation.

in progress

ISO 27001

Information-security management aligned to ISO 27001, with certification on our compliance roadmap.

on the roadmap

ISO 42001

The AI-governance standard. Our supervision, guardrail and audit features already map to its spirit; certification follows.

Your data stays yours.

The rules are simple, and they don't bend for us any more than they bend for your agents.

EU data residency

Customer data is hosted in the European Union. Open-source models run on our own EU infrastructure, so even inference can stay in Europe.

No training on your data

Your data is never used to train or fine-tune models — not ours, not any provider's. Model calls are inference only.

Encryption everywhere

TLS 1.2+ for every connection in transit; AES-256 encryption at rest across databases, files and backups.

Access under control

Least-privilege access internally, with production access limited to a small set of engineers. Support access to your workspace happens with your approval, and is logged.

Sign in your way

SSO through your identity provider (Microsoft Entra, Google), so joiners and leavers are governed where you already govern them.

Leave cleanly

Export your data at any time, and at contract end: full export on request, then permanent deletion on a documented schedule.

Tested, not assumed

Regular penetration testing by external specialists, continuous dependency and infrastructure scanning, and an assume-breach posture in design reviews.

And a layer nobody else has: the agents themselves.

Most security pages stop at infrastructure. Our riskiest actor is the agent — so it gets its own controls, in the product, visible to you.

Approval gates

Actions you designate — external messages, spending, record changes — wait for a named human's yes. How it works →

Company-wide guardrails

Off-limits topics and audiences, set once by admins, inherited by every agent. How it works →

AI supervisors

Independent supervision on every run, with the authority to stop an agent and ask. How it works →

Everything auditable

Every agent action and every human change, logged and answerable — "who did this?" always has an answer. How it works →

Common questions.

Where is our data stored?

In the EU. If you run open-source models with us, inference happens on our EU infrastructure too.

Is our data used for training?

No. Never — not by us, and not by the model providers we route to on your behalf.

What happens if we leave?

You take your data with you — full export — and we delete the rest permanently on a documented schedule.

Security questionnaire, DPA, or a deeper conversation: hello@agenthb.ai.

Control, all the way down.

The same demo that shows the product shows the controls. Bring your CISO.