Agent Dojo · Trust

Security posture.
Stated plainly.

Last reviewed 2026-06-21 · 30th Century Media Holdings Corp, doing business as Agent Dojo

Customer scope

Agent Dojo is offered to business-process outsourcing (BPO) companies in the Philippines. The Privacy Policy and DPA include defensive coverage for customers whose end clients sit in other jurisdictions; specific regional commitments (EU representative, HIPAA BAA, US state-law disclosures) are added on request as the customer roster expands.

Compliance posture

  • SOC 2

    Readiness — Type I targeted

    Policies signed, controls operating, evidence collected. Audit engagement begins when customer-required.

  • PH DPA (RA 10173)

    Primary jurisdiction — Philippine BPO customer base

    Privacy Policy + DPA align with the Philippine Data Privacy Act. Formal DPO designation + NPC registration deferred until headcount/revenue triggers.

  • GDPR / UK GDPR

    Defensive coverage — SCC + IDTA language in DPA

    No EEA/UK customers today. The DPA includes Standard Contractual Clauses + UK Addendum coverage so processing for a customer whose end clients sit in the EEA/UK is supported on request. EU representative designation deferred until first EEA customer onboards.

  • HIPAA

    Not yet — healthcare-tenant routing planned (Phase 5)

    No PHI is processed today. Synthetic scenarios only.

Policy
Operating
Evidenced
Type I
Type II

Trust services criteria

  • CC Security

    RLS-scoped tenancy, signed-cookie sessions, branch-protected releases, full-tree dependency audit.

  • A1 Availability

    Multi-region failover for compute, PITR on Postgres, synthetic health probe every 5 minutes.

  • C1 Confidentiality

    Transcripts and recordings encrypted at rest in Supabase Storage; tenant-scoped access enforced server-side.

  • P Privacy

    Data-handling controls (export, purge, classification) shipped; formal Privacy-criterion mapping pending customer request.

  • PI1 Processing Integrityout of scope

    Not in scope for v1. Scoring outputs include the model judgement and the version of the rubric used.

Subprocessors

Every third party that stores, processes, or transmits Agent Dojo or tenant data. Data-tier vendors touch confidential content. Operational-tier vendors do not.

Data tier

  • SupabaseData

    Postgres + Auth + Storage

    Data
    All tenant data — PII, transcripts, recordings
    Region
    AWS us-west / multi-region replicas
    SOC 2
    Type II
  • LiveKit CloudData

    Managed SFU (voice media)

    Data
    Live call audio (transient); recording egress
    Region
    Multi-region
    SOC 2
    Type II
  • AnthropicData

    Claude — scoring, assistant, voice LLM

    Data
    Transcripts, prompts, persona/rubric text
    Region
    US
    SOC 2
    Type II
  • AWS BedrockData

    Claude failover; data-tier path

    Data
    Transcripts, prompts
    Region
    us-east-1
    SOC 2
    Type II
  • ElevenLabsData

    Conversational AI voice

    Data
    Call audio + text
    Region
    US / EU
    SOC 2
    Type II
  • DeepgramData

    Speech-to-text (QA path)

    Data
    Call audio, transcripts
    Region
    US
    SOC 2
    Type II
  • CartesiaData

    Text-to-speech

    Data
    Text → synthesized audio
    Region
    US
    SOC 2
    Confirm
  • Google (Gemini)Data

    Image gen, QA transcription, voice analysis

    Data
    Images, audio, text
    Region
    Multi-region
    SOC 2
    Type II

Operational tier

  • VercelOperational

    Web hosting (Next.js)

    Data
    Request traffic, access logs — transient
    Region
    Global edge
    SOC 2
    Type II
  • Fly.ioOperational

    Voice + buddy worker compute

    Data
    Transient in-flight audio + scoped bearer token; no data at rest
    Region
    ISO 27001 data centers, multi-region
    SOC 2
    Type II
  • InngestOperational

    Background job orchestration

    Data
    Job payloads (tenant/session IDs)
    Region
    US
    SOC 2
    Type II
  • UpstashOperational

    Redis (rate-limit counters)

    Data
    Identifier keys only — no content data
    Region
    Global
    SOC 2
    Type II
  • ResendOperational

    Transactional email

    Data
    Email addresses; magic-link + help content
    Region
    US
    SOC 2
    Type II
  • Grafana CloudOperational

    Observability (logs, metrics, traces)

    Data
    Telemetry — PHI-prohibited by policy
    Region
    US / EU
    SOC 2
    Type II
  • StripeOperational

    Billing

    Data
    Payment data (Stripe is the PCI boundary)
    Region
    US
    SOC 2
    PCI DSS
  • GitHubOperational

    Source code + CI

    Data
    Source code; no production data
    Region
    US
    SOC 2
    Type II

Policies

Nineteen signed policies, reviewed annually. Available on request to current and prospective customers under NDA.

  1. 00
    Information Security Policy
    Governing rules and roles for security at Agent Dojo
  2. 01
    Access Control Policy
    How identities are provisioned, reviewed, and revoked
  3. 02
    Change Management Policy
    Pull-request review and CI gates before production
  4. 03
    Incident Response Policy
    Detection, response, and post-mortem expectations
  5. 04
    Vendor Management Policy
    Vetting and annual review of subprocessors
  6. 05
    Data Classification Policy
    Confidential, internal, and public data tiers
  7. 06
    Data Retention and Deletion Policy
    How long data is kept and how it is purged
  8. 07
    Backup and Disaster Recovery Policy
    Point-in-time recovery and the annual restore drill
  9. 08
    Risk Assessment Policy
    Annual risk register review with mitigations
  10. 09
    Cryptography Policy
    TLS, at-rest encryption, and key management
  11. 10
    Vulnerability Management Policy
    Dependency monitoring and patching cadence
  12. 11
    Asset Management Policy
    Endpoint and cloud-resource inventory
  13. 12
    Acceptable Use Policy
    Rules of the road for company devices and accounts
  14. 13
    Secure Development Policy
    SDLC controls including code review and testing
  15. 14
    Logging and Monitoring Policy
    What is logged, where, and how alerts are triaged
  16. 15
    Security Awareness and Training Policy
    Onboarding security training and annual refresher
  17. 16
    Personnel Security Policy
    Background checks, onboarding, and offboarding
  18. 17
    Business Continuity Policy
    How operations continue during disruption
  19. 18
    Privacy and Data Protection Policy
    Notice, consent, subject rights, and DPAs

Incident reporting

Report a suspected vulnerability or security issue to . We acknowledge within 24 hours and provide a written response with remediation status within five business days.

Responsible disclosure is welcomed. We will not pursue researchers who report in good faith and follow the practices described in our Incident Response Policy.

For buyers

Under NDA, we provide on request:

  • Latest SOC 2 readiness summary and control matrix.
  • Pre-signed Data Processing Agreement.
  • Penetration-test summary letter from our most recent engagement.
  • Architecture diagram covering data flow and tenancy boundaries.
  • Subprocessor change-notification commitment terms.

Send requests to with your company name and the artifact you need.

30th Century Media Holdings Corp
6406 Via Del Cerrito
Rancho Murieta, CA 95683, USA
Agent Dojo homeReviewed 2026-06-21