Trust Center
Trust and security
AgentStructure does not claim SOC 2, ISO 27001, HIPAA, or PCI DSS certification. Where a control is not yet operating, the page says it is a principle. Contact support@agentstructure.ai.
Security
Principles, not certifications.
Privacy
What this website collects and what it does not.
Data handling
Minimization, provenance, and authorized sources.
Responsible AI
Evidence, permissions, and human decisions.
Subprocessors
None listed for customer content.
Vulnerability reporting
How to report an issue in this website.
Data deletion
How to ask us to delete an inquiry.
Security
Last updated September 23, 2026
Certifications
AgentStructure does not claim SOC 2, ISO 27001, HIPAA, PCI DSS, or any other audit certification. If that changes, the report or the letter will be identified here. A principle is not a certification.
Principles
These are design rules for the infrastructure and for this website.
- Least-privilege access
- Minimized data collection
- Encrypted transport for production API calls
- Secure authentication before non-public tools
- Permission-scoped integrations
- Protection of API credentials, outside prompts
- Logging of material actions
- Retention controls, published before customer content is stored
- Separation between information retrieval and external actions
- Provenance for third-party data
- Authorized access only to external data sources
This website
The public site is a set of documents and a contact form that hands the message to your email client. It does not store uploads. It does not hold production data-feed credentials.
Reporting
See Vulnerability Disclosure, or email support@agentstructure.ai with the subject line "Security vulnerability".