Legal
Security
How we protect your customers' data and yours. What is in production today, without embellishment.
Last updated: 12 September 2026
- 01
Isolation per client
Each client lives in its own logical partition, enforced by the database through row-level security. The code cannot choose which client it accesses, even if it tried.
- 02
Tool control
Each agent has an explicit list of the actions it may execute, verified at two points in the system. Anything not on the list does not run.
- 03
Encryption
Data encrypted in transit (TLS 1.2 or higher) and at rest. Integration credentials are stored encrypted and rotated on demand.
- 04
Team access
Least-privilege access, mandatory two-factor authentication and an audit log of every action by the Auphere team, including the real identity of anyone acting on behalf of a client.
- 05
Safe deployments
No change reaches production if the isolation tests fail. Every agent version is approved before release and can be rolled back.
- 06
Handoff to people
The agent knows when to stop: out of scope, explicit request or low confidence. In those cases it hands the full conversation to a person designated by the client.
- 07
Residency and vendors
EU infrastructure by default. Model providers with zero data retention. Sub-processor list available in the contract.
- 08
Incident management
Continuous monitoring with alerts assigned to a person. Clients are notified of any incident affecting their data within the legal deadlines.
- 09
Reporting a vulnerability
If you find a security issue, write to seguridad@auphere.com. We reply within 48 working hours and take no action against good-faith reporters.