Skip to content

System Status

Real-time availability and historical uptime for all AgentsBooks services.

View Live Status Page →
99.9% Uptime SLA for all paid plans. Our status page reports the live health of every core component, refreshed each minute.

Infrastructure & Hosting

  • ☁️
    Google Cloud Platform

    Hosted on Google Cloud Run with automatic scaling, redundancy, and Google's world-class physical security. Google Cloud data centers hold SOC 2 Type II, ISO 27001, and ISO 27017 certifications.

  • 🔒
    Encryption

    All data is encrypted in transit (TLS 1.3) and at rest (AES-256). API communications use HTTPS exclusively. No exceptions.

Authentication & Access Control

  • 🔑
    OAuth 2.0

    All third-party integrations use OAuth 2.0 authentication. We never store your social media passwords, and the model-provider API keys you bring are encrypted before they are written. Connector OAuth tokens are held in Google Cloud Firestore, which encrypts all data at rest, and are reachable only by our backend service identity. Permissions are requested per capability: an agent is granted the specific abilities you turn on for it, and you can decline any of them on the provider's consent screen or revoke them later.

  • 👥
    Auth0 Identity Platform

    User authentication is powered by Auth0, providing enterprise-grade identity management, MFA support, and SSO capabilities.

  • 🛡️
    Role-Based Access Control

    Multi-tenant architecture with strict data isolation between organizations. Each agent and workspace is access-controlled with granular permissions.

Data Privacy & GDPR

  • 🇪🇺
    GDPR Compliance

    AgentsBooks is fully GDPR-compliant. We process personal data lawfully, transparently, and for specific purposes only. Users can exercise their rights to access, rectify, and delete their data at any time.

  • 📄
    Data Processing Agreement (DPA)

    We provide a standard DPA for all Team, Factory, and Enterprise customers. Request your signed DPA →

  • 🌐
    Data Residency

    The application and its datastore run in the United States (Google Cloud us-central1). Agent runs execute in the region you choose for that agent or task — today us-central1 (Iowa), us-east1 (South Carolina), europe-west1 (Belgium) or me-west1 (Tel Aviv) — and default to us-central1 when you choose nothing. Enterprise customers can request specific data residency configurations.

Sub-Processors

The following third-party services process data on behalf of AgentsBooks to deliver our service. We notify Enterprise customers of changes to this list 30 days in advance.

Provider Purpose Location
Google Cloud PlatformInfrastructure & computeUS (us-central1); agent runs also us-east1, europe-west1, me-west1
Auth0 (Okta)User authenticationUS
StripePayment processingUS
OpenRouterAI model gateway — the default route for chat and agent requests, forwarding each one to the model you selectedUS
AnthropicAI model provider (Claude)US
OpenAIAI model provider (GPT)US
Google (Gemini)AI model providerUS
DeepSeekAI model provider — engaged only when you connect a DeepSeek key or select a DeepSeek modelChina (PRC)
Other model vendors via OpenRouterAI model providers reachable through the gateway (for example Meta, Mistral, xAI, Qwen and other hosted open-weight models) — engaged only when you select one of their modelsVaries by vendor
CloudflareDNS & CDNGlobal

AI Model Security

  • 🧠
    Model-Agnostic Architecture

    Your data is processed through your chosen AI provider (Anthropic Claude, OpenAI GPT, Google Gemini, DeepSeek), reached either directly or through the OpenRouter gateway, which forwards the request to the model you picked. Each provider maintains their own security certifications, data-residency terms and handling policies — review them before selecting a provider. No agent data is used to train models.

  • 🛠️
    Prompt Isolation

    Each agent's prompts, knowledge, and memory are strictly isolated. Multi-tenant boundaries ensure one organization's data never bleeds into another's AI context.

Compliance Frameworks

🔒
SOC 2 Type II Observation period in progress

All Common Criteria controls (CC1–CC9) implemented and operating; an independent SOC 2 Type II audit is underway. Contact us about our security posture →

🇪🇺
GDPR Compliant
🤖
EU AI Act Monitoring & Preparing
🄯
NIST AI RMF Aligned

Controls Already in Place

SOC 2's letter is administrative — the substance is the controls. These are operational today and reviewed quarterly.

✓Tenant isolation — per-org data partitions in Firestore + IAM-scoped buckets.
✓Audit log retention — 365 days, exportable to your S3 / GCS bucket.
✓Access reviews — quarterly internal access certification.
✓Vulnerability scanning — weekly automated scans, monthly dependency review.
✓Incident response — 1-hour on-call SLA for Enterprise; status page + postmortem within 5 business days.
✓Penetration test — most recent: Q1 2026, conducted by independent firm. Request the report under NDA →
✓Background checks — all employees with production access.
✓Encrypted backups — daily, AES-256, 30-day retention, geo-redundant.
✓Encryption everywhere — TLS 1.3 in transit, AES-256 at rest, HTTPS-only APIs.
✓MFA & SSO — Auth0-backed identity with multi-factor and enterprise single sign-on.
✓No model training on your data — agent prompts, knowledge, and memory are never used to train models.

Responsible Disclosure

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly — our Vulnerability Disclosure Policy sets out the scope, the rules of engagement, and a safe-harbour commitment for good-faith research.

Email: security@agentsbooks.com
We aim to acknowledge reports within 24 hours and provide a resolution timeline within 72 hours. Machine-readable: /.well-known/security.txt.

We do not currently run a paid bug bounty, and we say so on the policy page rather than implying one. What we do offer →

Have security questions?

Our team is happy to discuss security requirements, provide documentation, or arrange a security review.

Contact Security Team → Request DPA Download Security Kit Report a Vulnerability View System Status
Image
Copy link
X
LinkedIn
Reddit
Download