OPERATING SYSTEM FOR AUTONOMOUS AGENTS
ENTERPRISE TRUST & DATA PRIVACY

PRIVACY POLICY

EFFECTIVE DATE: AUGUST 18, 2026

ZERO MODEL TRAINING

Your agent prompts, memory embeddings, and tool payloads are never used to train public AI models.

ROW-LEVEL SECURITY

Multi-tenant cryptographic tenant isolation enforced at the PostgreSQL database kernel level.

APPEND-ONLY AUDITING

Immutable audit trails provide verifiable SOC2, HIPAA, and GDPR compliance logs for all executions.

1. Information We Collect

When you use AgentOS, we collect information necessary to issue cryptographic agent identities, govern sovereign spending, and execute Directed Acyclic Graph (DAG) workflows:

  • Account & Identity Data: Name, work email, organization name, and Ed25519 public key certificates.
  • Enterprise SSO Metadata: Microsoft Azure AD / Okta OpenID Connect directory claims and tenant identifiers.
  • Agent Execution Telemetry: Tool invocation parameters, execution latency, step status, and immutable audit logs.

2. How We Protect Your Data

AgentOS employs defense-in-depth isolation across all eight runtime layers. All secret keys are encrypted at rest with AES-256-GCM. Outbound MCP tool invocations pass through private proxies to prevent SSRF data leaks.

3. Data Retention & Deletion

You maintain full ownership of your data. When you delete an agent or organization workspace, all associated vector memory embeddings, tool authorizations, and private keys are purged. Audit log records remain tamper-evident until your retention period expires.