Security that clears procurement
AgentLabz is designed for regulated environments: identity, access, encryption, isolation, and auditability are platform primitives, not add-ons.
AES-256
Encryption at rest
TLS 1.3
Encryption in transit
99.9%
Availability target
0
Customer data used for training
Twelve controls enterprise buyers ask for
Available across identity, data, deployment, and governance. Enterprise agreements add contractual commitments on top.
Encryption in Transit
All traffic between clients, our services, and model providers travels over TLS.
Encryption at Rest
Stored documents, embeddings, configurations, and logs are encrypted at rest.
Authentication
Identity-backed sign-in with session management, plus SSO for enterprise workspaces.
Role-Based Access Control
Workspace, agent, and tool-level roles with least-privilege defaults.
Audit Logging
Configuration changes, tool calls, and agent actions are recorded with actor and arguments.
Tenant Isolation
Workspace data, keys, and vector namespaces are logically separated per tenant.
Secrets Management
Credentials are stored encrypted and injected at call time — never held in plaintext or in client code.
Scoped Tool Permissions
Agents can only call the tools you grant, with approval gates available on privileged actions.
Data Retention Controls
Configurable retention windows for conversations, documents, and logs, with deletion on request.
Secure API Authentication
Scoped API keys per environment with rotation and last-used visibility.
No Training on Your Data
Customer documents, conversations, and configurations are never used to train shared models.
Isolated Deployments
Single-tenant and in-VPC deployment options for isolation-critical workloads, scoped per agreement.
app.agentlabz.tech / settings / team
app.agentlabz.tech / settings / api keys
production
alz_live_••••••••••••7f2a
staging
alz_test_••••••••••••91c4
ci-pipeline
alz_test_••••••••••••4b08
How we operate
Tenant isolation
Separate vector namespaces, database schemas, and encryption keys per workspace. No shared inference cache across tenants.
Model training
Customer documents, conversations, and configurations are never used to train shared models.
Least privilege
Every tool call carries an explicit scope. Privileged actions require an approval step recorded in the audit log.
Retention
Configurable retention windows for transcripts, traces, and knowledge artefacts, with verifiable deletion.
Vulnerability management
Dependency scanning, automated patching windows, and annual third-party penetration testing.
Incident response
Documented runbooks, on-call rotation, and contractual notification timelines for enterprise agreements.