Security & Compliance
Your data, our posture
AgentLedger processes agent activity logs, audit trails, and compliance metadata. This page states, plainly, what we handle and what we do not claim.
What we handle
We process AI-agent activity logs, audit trails, and compliance metadata. These may contain business-confidential information and potentially personal data if agent interactions involve user information.
Data handling commitments
- Audit logs are retained for your configured retention period (default 90 days) and can be exported or deleted at any time.
- We apply access controls consistent with GDPR Art. 32 (security of processing).
- BYOK keys are stored server-side only and never exposed to the browser.
Our compliance posture (honesty rule)
- AgentLedger is an audit logging tool, not a legal compliance guarantee. It records agent activity but does not ensure compliance with all applicable laws.
- We do not guarantee that audit trails will always be complete, do not claim "100% accurate logging", and do not state you will "never miss an audit requirement". Logging depends on the completeness of agent instrumentation.
- For binding compliance decisions, consult qualified legal and compliance professionals.
Subprocessors & payments
refs: GDPR Art. 32 · OWASP Top 10