Auphere

Legal

Security

How we protect your customers' data and yours. What is in production today, without embellishment.

Last updated: 12 September 2026

  1. 01

    Isolation per client

    Each client lives in its own logical partition, enforced by the database through row-level security. The code cannot choose which client it accesses, even if it tried.

  2. 02

    Tool control

    Each agent has an explicit list of the actions it may execute, verified at two points in the system. Anything not on the list does not run.

  3. 03

    Encryption

    Data encrypted in transit (TLS 1.2 or higher) and at rest. Integration credentials are stored encrypted and rotated on demand.

  4. 04

    Team access

    Least-privilege access, mandatory two-factor authentication and an audit log of every action by the Auphere team, including the real identity of anyone acting on behalf of a client.

  5. 05

    Safe deployments

    No change reaches production if the isolation tests fail. Every agent version is approved before release and can be rolled back.

  6. 06

    Handoff to people

    The agent knows when to stop: out of scope, explicit request or low confidence. In those cases it hands the full conversation to a person designated by the client.

  7. 07

    Residency and vendors

    EU infrastructure by default. Model providers with zero data retention. Sub-processor list available in the contract.

  8. 08

    Incident management

    Continuous monitoring with alerts assigned to a person. Clients are notified of any incident affecting their data within the legal deadlines.

  9. 09

    Reporting a vulnerability

    If you find a security issue, write to seguridad@auphere.com. We reply within 48 working hours and take no action against good-faith reporters.