Security & Trust

Security, boundaries and proof by design.

AgenticFy is built to prepare companies for AI agents without taking over payments, orders, inventory, customer data or uncontrolled actions. We are early, and we are explicit about exactly what we read, write, encrypt, log, prove, approve and never touch.

Data handling

What we collect is scoped to preparing your web presence for agents. We do not collect what we do not need.

CategoryWhat it isNotes
Domain and public site dataPublicly reachable pages of the domain you assessPublic data; read to score readiness
Assessment and proof dataScores, gaps, evidence references, journey replaysThe output of an assessment
Generated assetsEntity profile, Q&A, claim registry, manifestsGenerated from your assessment
Workspace and setup dataPlan, package, owners, setup choicesWhat drives activation
Integration metadataProvider, connection status, last errorBooleans and status, not secrets
Credential secretsProvider tokens you connectEncrypted at rest, never returned (see below)
Delivery and audit logsEmail/webhook deliveries, admin actionsFor operability and audit

Retention, deletion, export

  • ·Retention and deletion are configured by customer agreement; we do not impose a one-size policy here.
  • ·You can revoke a connected credential at any time; revocation is supported per provider.
  • ·Assessment and proof data can be exported (one-pager, proof package, JSON).

We use third-party APIs and model providers to do this work, so data is processed by those subprocessors (listed below). We do not claim data never leaves the environment.

Credential security

CredentialUsed forScope we ask for
Shopify admin tokenRead products / policies for commerce readinessRead; write only if you authorize publish
VTEX appKey / appTokenRead catalog / SKU / pricing / inventory / policyRead
Webflow tokenPublish content when explicitly connectedContent scope only
WordPress application passwordCreate a marked pagePage-create capability only
Stripe test secretTest payment rail only, if configuredTest mode only, never production
Google Search Console OAuthRead search performance signalsRead-only GSC scope

Permission boundaries

AgenticFy canAgenticFy never does
Read your public sitenever processes payments
Generate agent assetsnever moves money
Create a GitHub PR (you merge)never stores card data
Publish content when explicitly connectednever creates orders
Validate an installnever changes inventory
Monitor driftnever changes prices
Send signed webhooksnever issues refunds
Generate a proof packagenever accesses buyer PII unless explicitly scoped in future
Surface human approval pointsnever approves legal/compliance claims without human review
never exposes stored tokens
never declares readiness without evidence

Payment boundary

  • AgenticFy is not a payment processor and does not store card data.
  • Payment, order and inventory operations are blocked by design, not merely discouraged.

Human approval model

Evidence and audit

  • ·If AgenticFy cannot prove a claim, it marks it as not proven.

Webhook and integration security

Admin and internal operations

Subprocessors

Infrastructure and service providers we use:

Specific subprocessors may vary by deployment, customer configuration and connected integrations. We do not claim SOC 2, ISO 27001, PCI or HIPAA certification; we are early and say so plainly.

Security contact

For a security review or to report an issue, contact us and we will respond. A dedicated security contact is available on request.

DocsBoundariesPricing