AGI SALT, born in AI Connect with SALT

Trust

AGISALT Inc.
Last updated: 12 June 2026


Scope of this page

This page sets out AGISALT's security and governance position, its sub-processors, and the process for obtaining the underlying documents. It is provided for information and does not form part of any agreement between AGISALT and any customer, which is governed by the executed contract documents.

AGISALT services are built on Microsoft Azure, Microsoft 365 and Dynamics 365, and in a delivery engagement operate within the customer's own Microsoft tenant.


Platform certifications and audit reports

Certifications, audit reports and compliance documentation for Microsoft Azure, Microsoft 365 and Dynamics 365 are published by Microsoft at the Microsoft Trust Center and apply to Microsoft's services.

Enquiries relating to AGISALT's own security posture, and requests for the documents listed under *Requesting documents* below, may be directed to trust@agisalt.com.


How AGISALT deploys

In a delivery engagement, agents operate within the customer's Microsoft tenant, under the customer's Microsoft Entra ID and subject to the customer's Conditional Access policies. Customer data remains within that boundary and is not copied into an AGISALT environment for the purpose of delivering the services.

Certain AGISALT-operated surfaces run on AGISALT infrastructure. These include this website, the assistant on it, and AGISALT internal tooling. Conversations with the assistant are stored in AGISALT's Azure environment and not in your tenant.

Which of the two applies to a given service is identified in the applicable Statement of Work before execution.


Data handling

  1. Tenant boundary. In a delivery engagement, customer data remains within the customer's Microsoft tenant and subject to the customer's identity and access controls.
  2. No model training. AGISALT does not use customer data to train, fine-tune or evaluate any AI model, and does not permit its providers to do so, except under a separate written agreement that is specific to identified data and revocable by the customer at any time.
  3. Agent disclosure. Every customer agreement includes an AI and Agent Disclosure Addendum identifying the agents operating in the customer environment, their function, and the human review archetype applicable to each.
  4. Ownership. The customer owns its data and its configuration choices. AGISALT retains all right, title and interest in its Delivery OS, agent specifications and telemetry schemas.
  5. Sub-processor changes. AGISALT gives prior notice of sub-processor changes on the terms set out below.

AI governance

Transparency. AGISALT agents identify themselves as AI agents to any person interacting with them. This applies to the assistant on this site and to agents deployed in a customer engagement.

Human review of the assistant. AGISALT personnel review a sample of conversations with the assistant on this site. The assistant is not subject to real-time human review of each response, and its output may be inaccurate. Statements made by the assistant do not bind AGISALT and should not be relied upon. Any position required for a commercial or evaluation decision must be obtained from AGISALT in writing.


Sub-processors

AGISALT publishes the third parties engaged to process personal data on behalf of its customers, the service each provides, and the regions in which each operates.

AGISALT engages no other sub-processor for observability, support ticketing, identity or payment processing.

Notice of change. AGISALT gives 30 days' prior notice of the engagement of a new sub-processor or a material change in the scope of an existing engagement, and 15 days' notice of a routine change such as the addition of a region. Where a change is required urgently for security, legal compliance or service continuity, AGISALT gives such notice as is practicable together with the reason. A customer may object in writing on reasonable data-protection grounds, in which case the parties shall negotiate in good faith and, failing resolution, the affected services may be terminated.

To receive notice of changes to this register, email trust@agisalt.com.


Healthcare and regulated data

AGISALT's delivery model does not require protected health information to be transferred into AGISALT systems. Agents operate within the customer's Microsoft tenant, against the customer's systems and under the customer's identity controls, so protected health information remains in the customer's custody and subject to the customer's existing agreements with Microsoft.

Where an engagement requires AGISALT to create, receive, maintain or transmit protected health information on behalf of a covered entity, AGISALT will enter into a Business Associate Agreement as part of the engagement contract. AGISALT maintains its own BAA template and will review a customer's form. BAA terms are agreed in writing as part of the contracting process and cannot be agreed through this website or the assistant.

AGISALT makes no claim of HIPAA compliance or HIPAA certification. HIPAA provides for no such certification.


Security


Incident response


Reporting a vulnerability

Suspected security vulnerabilities in an AGISALT service or on this site should be reported to security@agisalt.com. AGISALT will acknowledge the report and provide updates on its status. Reporters are asked to allow AGISALT a reasonable period to remediate before public disclosure.

AGISALT will not pursue legal action against a researcher acting in good faith who avoids privacy violations and service disruption and who does not access, alter or destroy data belonging to any other person.

This undertaking does not extend to: social engineering of AGISALT personnel, customers or suppliers; physical attacks on persons or property; denial-of-service or load testing; high-volume automated scanning; or accessing, altering, destroying or exfiltrating data belonging to any other person. AGISALT reserves all rights and remedies in respect of such conduct.


Requesting documents

The following documents are available to customers and to prospective customers under a mutual non-disclosure agreement. Requests should be directed to trust@agisalt.com.


Corporate

Microsoft partnership. AGISALT Inc. is a Microsoft Solutions Partner with designations in Data & AI (Azure), Digital & App Innovation (Azure), and Business Applications. These designations are held by AGISALT Inc., which is also the contracting entity. AGISALT will provide its Partner Center record on request.


Contact

Security and trust: trust@agisalt.com
Vulnerability reports: security@agisalt.com
Privacy and data rights: privacy@agisalt.com
Legal: legal@agisalt.com

AGISALT Inc., 700 Commerce Drive, Suite 500, Oak Brook, IL 60523, United States