Security and governance

Security you can inspect. Controls you can own.

TrendsAGI separates product safeguards, deployment choices, and customer responsibilities so technical and governance teams can evaluate the system without guesswork.

Security posture

Customer-hosted option
Documented control mappings
Reviewable evidence workflows
Request a security review
Control map

Protection across the full data path.

Each layer has a clear purpose, an operator, and evidence that can be reviewed during an assessment.

01

Identity and access

Scoped identities, least-privilege roles, session controls, and reviewable access paths.

  • Role-based access
  • Scoped service identities
  • Session hardening
02

Encryption and keys

Protected network paths and encrypted storage with clear credential ownership boundaries.

  • TLS-protected transport
  • Encrypted storage
  • Secret separation
03

Tenant boundaries

Account-scoped credentials and segmented application paths help keep customer data isolated.

  • Scoped credentials
  • Environment separation
  • Retention controls
04

Audit and monitoring

Operational events, alert thresholds, and evidence collection support investigation and review.

  • Centralised telemetry
  • Alerting paths
  • Evidence collection
05

Resilience

Health checks, recovery procedures, and deployment options keep operational risk visible.

  • Service health checks
  • Recovery runbooks
  • Deployment flexibility
06

Privacy operations

Documented intake and deletion workflows support data-subject and consumer privacy requests.

  • Request verification
  • Deletion workflow
  • Completion records
Shared responsibility

Know exactly where your boundary starts.

Cloud, hybrid, and customer-hosted deployments have different owners. We make those responsibilities explicit before rollout.

Inspect the open-source client
01

Choose the deployment

Select cloud, hybrid, or customer-hosted boundaries based on your data and operational requirements.

02

Assign each control

Document who owns identity, secrets, infrastructure, monitoring, retention, and incident response.

03

Collect the evidence

Use repeatable checks and review artefacts to support your organisation’s own assurance process.

Governance mapping

A practical path to assurance.

The mapping below shows how operational controls can support SOC 2 criteria and privacy obligations. Certification or legal compliance still depends on your deployment, policies, evidence, and independent assessment.

Control domainSOC 2 alignmentPrivacy supportReview evidence
Access governanceLeast privilege and access reviewRole-scoped personal-data accessIdentity configuration and access events
Data lifecycleClassification, retention, and disposalMinimisation and storage limitationRetention policy and deletion records
ProtectionTransport and storage safeguardsSecurity of processing measuresConfiguration and control review output
MonitoringEvents, alerts, and incident handlingAccountability and investigation traceLogs, alerts, cases, and runbook output
Privacy requestsDefined ownership and operating procedureAccess and deletion request handlingVerified request and completion history
Security review

Bring your architecture and control questions.

Talk to the team