Identity and access
Scoped identities, least-privilege roles, session controls, and reviewable access paths.
- Role-based access
- Scoped service identities
- Session hardening
TrendsAGI separates product safeguards, deployment choices, and customer responsibilities so technical and governance teams can evaluate the system without guesswork.
Security posture
Each layer has a clear purpose, an operator, and evidence that can be reviewed during an assessment.
Scoped identities, least-privilege roles, session controls, and reviewable access paths.
Protected network paths and encrypted storage with clear credential ownership boundaries.
Account-scoped credentials and segmented application paths help keep customer data isolated.
Operational events, alert thresholds, and evidence collection support investigation and review.
Health checks, recovery procedures, and deployment options keep operational risk visible.
Documented intake and deletion workflows support data-subject and consumer privacy requests.
Cloud, hybrid, and customer-hosted deployments have different owners. We make those responsibilities explicit before rollout.
Inspect the open-source clientSelect cloud, hybrid, or customer-hosted boundaries based on your data and operational requirements.
Document who owns identity, secrets, infrastructure, monitoring, retention, and incident response.
Use repeatable checks and review artefacts to support your organisation’s own assurance process.
The mapping below shows how operational controls can support SOC 2 criteria and privacy obligations. Certification or legal compliance still depends on your deployment, policies, evidence, and independent assessment.
| Control domain | SOC 2 alignment | Privacy support | Review evidence |
|---|---|---|---|
| Access governance | Least privilege and access review | Role-scoped personal-data access | Identity configuration and access events |
| Data lifecycle | Classification, retention, and disposal | Minimisation and storage limitation | Retention policy and deletion records |
| Protection | Transport and storage safeguards | Security of processing measures | Configuration and control review output |
| Monitoring | Events, alerts, and incident handling | Accountability and investigation trace | Logs, alerts, cases, and runbook output |
| Privacy requests | Defined ownership and operating procedure | Access and deletion request handling | Verified request and completion history |