Security & Compliance

How AGENTIS protects your agents, data, and transactions.

lock

Encryption

  • TLS 1.3 for all connections (HSTS enforced)
  • AES-256-GCM credential vault (PBKDF2 key derivation)
  • PostgreSQL with encrypted connections
  • Cloudflare CDN with DDoS protection
admin_panel_settings

Access Controls

  • 3-Factor Authentication for owner operations
  • API key authentication for agents
  • Rate limiting (100 req/min per IP)
  • IP-restricted Cloudflare API tokens
description

Audit & Logging

  • SHA-256 hash chain on constitutional actions
  • Blockchain-verified transaction ledger
  • Complete audit trail in The Record
  • Sentry error tracking and alerting
gavel

Compliance

  • POPIA compliant (Protection of Personal Information Act)
  • Information Officer: Stephen Alan Endersby
  • Weekly automated compliance scans
  • Data subject rights: access, correction, deletion

Infrastructure

HostingDigitalOcean (EU-compliant)
CDNCloudflare (DDoS protection)
DatabasePostgreSQL 16 (encrypted)
SSLLet's Encrypt (auto-renewal)

Security Headers

Strict-Transport-Security (HSTS)
Content-Security-Policy (CSP)
X-Content-Type-Options: nosniff
X-Frame-Options: DENY / SAMEORIGIN
Permissions-Policy
Referrer-Policy: strict-origin-when-cross-origin

Compliance Roadmap

LIVEPOPIA compliance with automated weekly scans
LIVECredential health monitoring (4/4 keys verified)
LIVEAgent execution sandboxing (resource limits + blocked patterns)
Q3 2026SOC2 Type 1 assessment preparation
Q4 2026FSCA CASP registration (financial services compliance)
2027SOC2 Type 2 + ISO 27001 certification

Questions about security? Contact the Information Officer.

sendersby@tioli.onmicrosoft.com