Security is the product.
Agenthub exists so companies can hand real work to agents without losing control. That promise starts below the features: where your data lives, who can touch it, and what happens when you leave.
Certified & compliant.
We operate from the EU, under EU law, and are working with independent auditors to certify what we already practice.
GDPR
Built and operated under GDPR from day one: EU establishment, EU hosting, data-processing agreements, and documented subprocessors.
SOC 2 Type II
Controls are implemented and the audit process is underway. Ask us for current status and our security documentation.
ISO 27001
Information-security management aligned to ISO 27001, with certification on our compliance roadmap.
ISO 42001
The AI-governance standard. Our supervision, guardrail and audit features already map to its spirit; certification follows.
Your data stays yours.
The rules are simple, and they don't bend for us any more than they bend for your agents.
Customer data is hosted in the European Union. Open-source models run on our own EU infrastructure, so even inference can stay in Europe.
Your data is never used to train or fine-tune models — not ours, not any provider's. Model calls are inference only.
TLS 1.2+ for every connection in transit; AES-256 encryption at rest across databases, files and backups.
Least-privilege access internally, with production access limited to a small set of engineers. Support access to your workspace happens with your approval, and is logged.
SSO through your identity provider (Microsoft Entra, Google), so joiners and leavers are governed where you already govern them.
Export your data at any time, and at contract end: full export on request, then permanent deletion on a documented schedule.
Regular penetration testing by external specialists, continuous dependency and infrastructure scanning, and an assume-breach posture in design reviews.
And a layer nobody else has: the agents themselves.
Most security pages stop at infrastructure. Our riskiest actor is the agent — so it gets its own controls, in the product, visible to you.
Approval gates
Actions you designate — external messages, spending, record changes — wait for a named human's yes. How it works →
Company-wide guardrails
Off-limits topics and audiences, set once by admins, inherited by every agent. How it works →
AI supervisors
Independent supervision on every run, with the authority to stop an agent and ask. How it works →
Everything auditable
Every agent action and every human change, logged and answerable — "who did this?" always has an answer. How it works →
Common questions.
In the EU. If you run open-source models with us, inference happens on our EU infrastructure too.
No. Never — not by us, and not by the model providers we route to on your behalf.
You take your data with you — full export — and we delete the rest permanently on a documented schedule.
Security questionnaire, DPA, or a deeper conversation: hello@agenthb.ai.
Control, all the way down.
The same demo that shows the product shows the controls. Bring your CISO.