Blog

What happens to your data on Agent200

What Agent200 stores to operate, what only passes through, what never happens, and the controls around all of it.

2 min read

A clear glass cube with a small green core at its centre

When your agent reaches into a user’s accounts through a platform, a reasonable question follows: what happens to that data on the way? Here is what Agent200 keeps, what it does not, and the controls around both.

What Agent200 stores to operate

A platform that manages identity and configuration has to keep some records. Agent200 stores:

  • developer accounts and project configurations,
  • API key records,
  • OAuth connection information and tokens,
  • the mapping between end users and their connections,
  • connector and workflow configurations,
  • usage and billing information.

These are the records that let a request for one user run on that user’s accounts, with your configuration, on your bill.

What passes through

When a tool runs, Agent200 retrieves the data from the provider and hands it to the model within the same request, then returns the result to your application. Your queries and responses are processed in real time and never stored.

What never happens

  • No training. Your data is never used to train AI models.
  • No cross-user access. Each user’s data is encrypted with individual keys, not just tenant-level isolation, and a request for one user never touches another user’s connections.
  • No access beyond what was granted. Users only see data already authorized in the source systems.

The controls around it

Control What it means
SOC 2 Type II Attested by AICPA, Type II
AES-256 encryption All data encrypted at rest with a FIPS 140-2 validated crypto module
TLS 1.3+ All data in transit encrypted
GDPR Customer data is maintained and secured in accordance with the EU’s General Data Protection Regulation
Granular access controls You choose services and endpoints per project and per workflow, down to the individual operation

A note on iGPT

iGPT, the premium email connector, indexes the email a user connects to it, because answering from an index is what makes it fast and precise. That indexing is iGPT’s job for the sources connected to it, with access by OAuth only, per-user isolation, and no use of the data for training.

For your security review

Bring your questions: the Security page covers the full list of measures, and you can request the SOC 2 Type II report.

Stacks of envelopes being organised into an index card cabinet with green tabs
Product

iGPT: your agent’s email context in one request

iGPT is a premium connector on Agent200. It indexes your users' email, threads and attachments, and answers your agent with cited, structured context in…

1 min read

Five frosted glass lenses of different shapes in a row, one with a green edge
Guides

Choosing a web search API for your agent

Tavily, Exa, Brave Search, Perplexity and Firecrawl each lean toward a different part of search. How to pick for your agent, and why you…

2 min read

200 OK

Build the agent.
Access everything it needs.

Bring the agent you already have. Agent200 provides and executes its external capabilities.

Book a demo.
See it in action.

Tell us who you are, then pick a time for a 1:1 session with an expert from our team.

We use your details only to email you about Agent200. See the Privacy Policy.

Pick a time. We'll take it from there.

A 1:1 session with an expert from our team, about what you are building.

Open in Calendly (opens in a new tab)