Security at Agnostics
How we handle target data, isolate workspaces, and what scans can and cannot prove.
Overview
Agnostics provides scan-based adversarial testing, findings, Release Gate recommendations, retests, and release reports for AI applications.
Results are informational and decision-support only. Agnostics does not provide legal advice, compliance certification, security certification, penetration testing certification, or release approval.
This page describes security controls we implement today. It is not a certification, audit report, or guarantee.
Organization-scoped access
Account access is role-based within organizations. Owners, admins, members, and viewers see only the projects and scans their role permits.
Cross-tenant access is denied at the application layer and through database row-level security policies.
Target configuration and validation
Target configuration you provide is stored in your organization workspace and used only to run scans you initiate.
We validate target URLs to block unsafe schemes, private network addresses, and common SSRF targets in production.
Target validation and scan dispatch are rate limited to reduce abuse.
Encryption and secrets
Data is encrypted in transit using TLS.
Target credentials and other sensitive configuration values are encrypted at rest before storage.
Secrets are decrypted only when needed to validate a connection or run a scan. They are not returned to the client after save.
Scan execution controls
Scans require organization context, entitlements, and server-side authorization.
Scan concurrency limits apply per organization and target. Duplicate in-flight scans are blocked where configured.
Platform kill switches can pause scan dispatch during incidents.
Billing security
Payments are processed by Stripe. Agnostics does not store full payment card numbers.
Entitlements are derived from server-side billing state verified through Stripe webhooks, not from browser redirects alone.
Report sharing
Report share links expose only the report snapshot you choose to share, subject to expiry and revocation settings you control.
Shared report routes are marked noindex and should be treated as confidential links.
Audit logging and abuse protection
Security-sensitive actions such as billing changes, scan dispatch, and admin overrides are logged for investigation.
Rate limits and abuse controls protect shared infrastructure.
Customer responsibility
You may only test targets you own or have explicit permission to test.
You remain responsible for your AI product, target configuration, permissions, policies, release decisions, customer communications, and applicable law.
Scans are limited to selected targets, configured attack packs, scan scope, and available product capability. Agnostics does not guarantee detection of every issue, vulnerability, misuse path, or failure.
Security incidents
Report a security concern through the Contact page (/contact) and choose Security concern.
We investigate good-faith reports and will contact you about confirmed issues affecting your workspace when appropriate.
Honest limitations
No online service can guarantee absolute security.
We do not claim certifications we have not earned.
Scans surface real failures with evidence. They cannot find every possible issue.