Trust
AGISALT Inc.
Last updated: 12 June 2026
Scope of this page
This page sets out AGISALT's security and governance position, its sub-processors, and the process for obtaining the underlying documents. It is provided for information and does not form part of any agreement between AGISALT and any customer, which is governed by the executed contract documents.
AGISALT services are built on Microsoft Azure, Microsoft 365 and Dynamics 365, and in a delivery engagement operate within the customer's own Microsoft tenant.
Platform certifications and audit reports
Certifications, audit reports and compliance documentation for Microsoft Azure, Microsoft 365 and Dynamics 365 are published by Microsoft at the Microsoft Trust Center and apply to Microsoft's services.
Enquiries relating to AGISALT's own security posture, and requests for the documents listed under *Requesting documents* below, may be directed to trust@agisalt.com.
How AGISALT deploys
In a delivery engagement, agents operate within the customer's Microsoft tenant, under the customer's Microsoft Entra ID and subject to the customer's Conditional Access policies. Customer data remains within that boundary and is not copied into an AGISALT environment for the purpose of delivering the services.
Certain AGISALT-operated surfaces run on AGISALT infrastructure. These include this website, the assistant on it, and AGISALT internal tooling. Conversations with the assistant are stored in AGISALT's Azure environment and not in your tenant.
Which of the two applies to a given service is identified in the applicable Statement of Work before execution.
Data handling
- Tenant boundary. In a delivery engagement, customer data remains within the customer's Microsoft tenant and subject to the customer's identity and access controls.
- No model training. AGISALT does not use customer data to train, fine-tune or evaluate any AI model, and does not permit its providers to do so, except under a separate written agreement that is specific to identified data and revocable by the customer at any time.
- Agent disclosure. Every customer agreement includes an AI and Agent Disclosure Addendum identifying the agents operating in the customer environment, their function, and the human review archetype applicable to each.
- Ownership. The customer owns its data and its configuration choices. AGISALT retains all right, title and interest in its Delivery OS, agent specifications and telemetry schemas.
- Sub-processor changes. AGISALT gives prior notice of sub-processor changes on the terms set out below.
AI governance
| Control | Status |
|---|---|
| Responsible AI Policy (public) | Drafted, available on request |
| AI Governance Policy (internal) | Drafted, available on request under NDA |
| AI and Agent Disclosure Addendum | Drafted, attached to every customer agreement |
| Human-in-the-loop review archetype per agent (Approver, Spot-checker, Exception-handler, Director) | Documented per agent |
| Telemetry and audit logging standard | Drafted |
| Model and system card per agent | Template drafted |
| Bias, fairness and red-team testing protocols | Drafted |
| AI incident response plan | Drafted |
| EU AI Act mapping | Drafted |
| NIST AI Risk Management Framework mapping | Drafted |
Transparency. AGISALT agents identify themselves as AI agents to any person interacting with them. This applies to the assistant on this site and to agents deployed in a customer engagement.
Human review of the assistant. AGISALT personnel review a sample of conversations with the assistant on this site. The assistant is not subject to real-time human review of each response, and its output may be inaccurate. Statements made by the assistant do not bind AGISALT and should not be relied upon. Any position required for a commercial or evaluation decision must be obtained from AGISALT in writing.
Sub-processors
AGISALT publishes the third parties engaged to process personal data on behalf of its customers, the service each provides, and the regions in which each operates.
| Sub-processor | Service | Regions |
|---|---|---|
| Microsoft Corporation | Cloud hosting (Azure), identity (Microsoft Entra ID), collaboration and support (Microsoft 365), observability, and foundation model inference (Azure OpenAI Service) | US, EU, UK, India as applicable |
AGISALT engages no other sub-processor for observability, support ticketing, identity or payment processing.
Notice of change. AGISALT gives 30 days' prior notice of the engagement of a new sub-processor or a material change in the scope of an existing engagement, and 15 days' notice of a routine change such as the addition of a region. Where a change is required urgently for security, legal compliance or service continuity, AGISALT gives such notice as is practicable together with the reason. A customer may object in writing on reasonable data-protection grounds, in which case the parties shall negotiate in good faith and, failing resolution, the affected services may be terminated.
To receive notice of changes to this register, email trust@agisalt.com.
Healthcare and regulated data
AGISALT's delivery model does not require protected health information to be transferred into AGISALT systems. Agents operate within the customer's Microsoft tenant, against the customer's systems and under the customer's identity controls, so protected health information remains in the customer's custody and subject to the customer's existing agreements with Microsoft.
Where an engagement requires AGISALT to create, receive, maintain or transmit protected health information on behalf of a covered entity, AGISALT will enter into a Business Associate Agreement as part of the engagement contract. AGISALT maintains its own BAA template and will review a customer's form. BAA terms are agreed in writing as part of the contracting process and cannot be agreed through this website or the assistant.
AGISALT makes no claim of HIPAA compliance or HIPAA certification. HIPAA provides for no such certification.
Security
| Area | Position |
|---|---|
| Identity and access | Microsoft Entra ID; least privilege; multi-factor authentication for AGISALT staff |
| Encryption | In transit and at rest, using the Microsoft platform defaults for the services in use |
| Logging and monitoring | Telemetry and audit logging standard applied to agent operations |
| Information Security Policy | Drafted, available on request under NDA |
| Vendor risk management | Policy drafted; sub-processors under contractual security obligations |
| Business continuity and disaster recovery | Plan drafted, available on request under NDA |
| Personnel | Confidentiality and IP assignment agreements for all staff and contractors; AI use policy for employees |
Incident response
- AGISALT maintains a written breach notification plan.
- Where AGISALT acts as a processor, AGISALT notifies the customer without undue delay after becoming aware of a personal data breach, and provides the information the customer requires to meet its own notification obligations, including the 72-hour obligation under Article 33 of the GDPR where applicable to that customer.
- Where a Business Associate Agreement is in place, AGISALT notifies in accordance with 45 C.F.R. § 164.410.
- AGISALT maintains a separate AI incident response plan covering agent-specific failure modes.
Reporting a vulnerability
Suspected security vulnerabilities in an AGISALT service or on this site should be reported to security@agisalt.com. AGISALT will acknowledge the report and provide updates on its status. Reporters are asked to allow AGISALT a reasonable period to remediate before public disclosure.
AGISALT will not pursue legal action against a researcher acting in good faith who avoids privacy violations and service disruption and who does not access, alter or destroy data belonging to any other person.
This undertaking does not extend to: social engineering of AGISALT personnel, customers or suppliers; physical attacks on persons or property; denial-of-service or load testing; high-volume automated scanning; or accessing, altering, destroying or exfiltrating data belonging to any other person. AGISALT reserves all rights and remedies in respect of such conduct.
Requesting documents
The following documents are available to customers and to prospective customers under a mutual non-disclosure agreement. Requests should be directed to trust@agisalt.com.
| Document | Availability |
|---|---|
| Information Security Policy | Under NDA |
| Responsible AI Policy | Public on request |
| AI Governance Policy | Under NDA |
| Data Processing Agreement | On request |
| AI and Agent Disclosure Addendum | On request |
| Sub-Processor Register | Public, above |
| Business Continuity and DR Plan | Under NDA |
| Breach Notification Plan summary | Under NDA |
| Certificate of Insurance | On request |
| Completed CAIQ Lite security questionnaire | Under NDA |
Corporate
| Legal entity | AGISALT Inc. |
| Jurisdiction | Delaware, United States |
| Type | C Corporation |
| Principal office | 700 Commerce Drive, Suite 500, Oak Brook, IL 60523, United States |
| Website | agisalt.com |
Microsoft partnership. AGISALT Inc. is a Microsoft Solutions Partner with designations in Data & AI (Azure), Digital & App Innovation (Azure), and Business Applications. These designations are held by AGISALT Inc., which is also the contracting entity. AGISALT will provide its Partner Center record on request.
Contact
Security and trust: trust@agisalt.com
Vulnerability reports: security@agisalt.com
Privacy and data rights: privacy@agisalt.com
Legal: legal@agisalt.com
AGISALT Inc., 700 Commerce Drive, Suite 500, Oak Brook, IL 60523, United States