Agent Dojo · Trust
Security posture.
Stated plainly.
Customer scope
Agent Dojo is offered to business-process outsourcing (BPO) companies in the Philippines. The Privacy Policy and DPA include defensive coverage for customers whose end clients sit in other jurisdictions; specific regional commitments (EU representative, HIPAA BAA, US state-law disclosures) are added on request as the customer roster expands.
Compliance posture
- SOC 2
Readiness — Type I targeted
Policies signed, controls operating, evidence collected. Audit engagement begins when customer-required.
- PH DPA (RA 10173)
Primary jurisdiction — Philippine BPO customer base
Privacy Policy + DPA align with the Philippine Data Privacy Act. Formal DPO designation + NPC registration deferred until headcount/revenue triggers.
- GDPR / UK GDPR
Defensive coverage — SCC + IDTA language in DPA
No EEA/UK customers today. The DPA includes Standard Contractual Clauses + UK Addendum coverage so processing for a customer whose end clients sit in the EEA/UK is supported on request. EU representative designation deferred until first EEA customer onboards.
- HIPAA
Not yet — healthcare-tenant routing planned (Phase 5)
No PHI is processed today. Synthetic scenarios only.
- Policy
- Operating
- Evidenced
- Type I
- Type II
Trust services criteria
- CC Security
RLS-scoped tenancy, signed-cookie sessions, branch-protected releases, full-tree dependency audit.
- A1 Availability
Multi-region failover for compute, PITR on Postgres, synthetic health probe every 5 minutes.
- C1 Confidentiality
Transcripts and recordings encrypted at rest in Supabase Storage; tenant-scoped access enforced server-side.
- P Privacy
Data-handling controls (export, purge, classification) shipped; formal Privacy-criterion mapping pending customer request.
- PI1 Processing Integrityout of scope
Not in scope for v1. Scoring outputs include the model judgement and the version of the rubric used.
Subprocessors
Every third party that stores, processes, or transmits Agent Dojo or tenant data. Data-tier vendors touch confidential content. Operational-tier vendors do not.
Data tier
- SupabaseData
Postgres + Auth + Storage
- LiveKit CloudData
Managed SFU (voice media)
- AnthropicData
Claude — scoring, assistant, voice LLM
- AWS BedrockData
Claude failover; data-tier path
- ElevenLabsData
Conversational AI voice
- DeepgramData
Speech-to-text (QA path)
- CartesiaData
Text-to-speech
- Google (Gemini)Data
Image gen, QA transcription, voice analysis
Operational tier
- VercelOperational
Web hosting (Next.js)
- Fly.ioOperational
Voice + buddy worker compute
- InngestOperational
Background job orchestration
- UpstashOperational
Redis (rate-limit counters)
- ResendOperational
Transactional email
- Grafana CloudOperational
Observability (logs, metrics, traces)
- StripeOperational
Billing
- GitHubOperational
Source code + CI
Policies
Nineteen signed policies, reviewed annually. Available on request to current and prospective customers under NDA.
- 00Information Security PolicyGoverning rules and roles for security at Agent Dojo
- 01Access Control PolicyHow identities are provisioned, reviewed, and revoked
- 02Change Management PolicyPull-request review and CI gates before production
- 03Incident Response PolicyDetection, response, and post-mortem expectations
- 04Vendor Management PolicyVetting and annual review of subprocessors
- 05Data Classification PolicyConfidential, internal, and public data tiers
- 06Data Retention and Deletion PolicyHow long data is kept and how it is purged
- 07Backup and Disaster Recovery PolicyPoint-in-time recovery and the annual restore drill
- 08Risk Assessment PolicyAnnual risk register review with mitigations
- 09Cryptography PolicyTLS, at-rest encryption, and key management
- 10Vulnerability Management PolicyDependency monitoring and patching cadence
- 11Asset Management PolicyEndpoint and cloud-resource inventory
- 12Acceptable Use PolicyRules of the road for company devices and accounts
- 13Secure Development PolicySDLC controls including code review and testing
- 14Logging and Monitoring PolicyWhat is logged, where, and how alerts are triaged
- 15Security Awareness and Training PolicyOnboarding security training and annual refresher
- 16Personnel Security PolicyBackground checks, onboarding, and offboarding
- 17Business Continuity PolicyHow operations continue during disruption
- 18Privacy and Data Protection PolicyNotice, consent, subject rights, and DPAs
Incident reporting
Report a suspected vulnerability or security issue to security@agentdojo.atlassian.net. We acknowledge within 24 hours and provide a written response with remediation status within five business days.
Responsible disclosure is welcomed. We will not pursue researchers who report in good faith and follow the practices described in our Incident Response Policy.
For buyers
Under NDA, we provide on request:
- Latest SOC 2 readiness summary and control matrix.
- Pre-signed Data Processing Agreement.
- Penetration-test summary letter from our most recent engagement.
- Architecture diagram covering data flow and tenancy boundaries.
- Subprocessor change-notification commitment terms.
Send requests to security@agentdojo.atlassian.net with your company name and the artifact you need.