AGICOMPLY
Client LoginBook Founder Triage
AGICOMPLY TRUST CENTER

Evaluate the evidence environment before you rely on it.

Security, privacy, evidence handling, tenant segregation, package integrity, and procurement documentation presented with implementation status and explicit limitations.

Open Procurement Vault What AGICOMPLY EstablishesRequest controlled documents
ASSURANCE BOUNDARYAGICOMPLY produces procurement-grade evidence packages used in review. It does not certify legal compliance, issue an ATO, or represent government approval.Read the authoritative boundary →
IMPLEMENTED CONTROLS

Current production properties.

These statements describe implemented product behavior. They are not third-party certifications.

Authenticated, tenant-segregated access

Organization-scoped records are separated through application authorization and Postgres Row Level Security policies.

Implemented

Evidence content hashes

Recorded evidence artifacts include SHA-256 content hashes where the ingestion workflow captures them.

Implemented

Append-only review history

Relevant review activity is recorded in append-only audit structures and package-specific examination records.

Implemented

Package-scoped reviewer access

External reviewer invitations are bounded to one issued package, time-limited, revocable, and stored using hashed access tokens.

Implemented

Secure account recovery

Password recovery uses time-limited Supabase recovery flows and requires a genuine recovery session before password replacement.

Implemented
CONTROLLED PROCUREMENT MATERIALS

Documents available for qualified review.

Some materials are supplied directly so access can be recorded and the current version can be confirmed.

Standard statement of work for the $3,500 ATO Readiness BaselineAvailable on request
Evidence-handling schedule and assessment boundaryAvailable on request
Privacy notice and subprocessor statementAvailable on request
Security architecture summaryAvailable on request
Standard confidentiality agreementAvailable on request
Data-processing terms for qualified procurement reviewAvailable on request
Request the procurement document set
DATA AND REVIEW BOUNDARIES

What AGICOMPLY does and does not claim.

Open the canonical claim boundary

Organization-scoped processing

Application records are associated with an organization identifier and subject to tenant-scoped access controls.

Point-in-time package integrity

Issued packages preserve a manifest hash and bounded package metadata for later verification.

Human verification boundary

Only human-accepted mappings are presented as affirmative supporting relationships in issued package records.

No continuous-control claim

The Baseline is a point-in-time evidence-readiness assessment. It does not establish continuous effectiveness or monitor the originating AI system runtime.

PLANNED ASSURANCE MATURITY

Published without implying completion.

These capabilities are planned or customer-demand dependent. They are not represented as currently implemented.

Independent application-security assessmentPlanned
Public service-status historyPlanned
Enterprise SAML and SCIMPlanned
Configurable evidence-retention administrationPlanned
Formal vulnerability-disclosure program expansionPlanned
SECURITY AND PRIVACY CONTACT

Route review questions to a controlled owner.

Use the company-domain contact for security, privacy, procurement documentation, or evidence-handling questions.

support@agicomply.comSecurity, privacy, trust, and procurement document requests
Send request