Security and compliance controls for agent AI workflows.
AgentAssist is built around organization boundaries, source-backed AI, audit evidence, and operational visibility for teams that need reviewable answers.
Tenant-scoped access
Organization membership, roles, and permission checks guard documents, AI conversations, billing, settings, and admin workflows.
Source-grounded AI
RAG responses include retrieval metadata and citations, with no-context and no-advice guardrails for customer-facing workflows.
Audit evidence
Sensitive actions such as uploads, deletes, exports, billing changes, support access, and SuperAdmin settings are logged.
Operational readiness
Worker queues, retry controls, performance snapshots, security audit gates, and retained load evidence are tracked for release readiness.
Data handling summary
Customer documents are organization-scoped and used to power retrieval, summaries, comparisons, analytics, and compliance workflows. They are not used to train public foundation models.
Trust documents
Review the core legal, privacy, support, subprocessor, and status resources used during customer security review.
Privacy Policy
How AgentAssist handles account, document, AI, billing, and audit data.
Terms and Conditions
Service terms, acceptable use, AI review rules, and organization responsibility.
Refund Policy
Organization subscriptions, failed payments, duplicate payments, and plan changes.
Privacy Requests
Access, export, correction, deletion, and organization-owned data request handling.
Retention Policy
Retention for documents, chunks, conversations, citations, audit logs, and backups.
Subprocessors
Infrastructure, AI, storage, auth, billing, and email providers used by AgentAssist.
Support Policy
Support scope, escalation expectations, and no-advice boundaries.
System Status
Public service health for AgentAssist surfaces.
Identity and access
- Authenticated access through Better Auth session controls.
- Organization membership required for tenant resources.
- Role and permission checks for billing, settings, documents, exports, and SuperAdmin surfaces.
- Support access is intended to be reasoned, limited, and auditable.
Document and AI handling
- Uploaded documents are scoped to the owning organization.
- Document chunks and citations are used for retrieval-grounded answers.
- Customer documents are not used to train public foundation models.
- AI output is assistance only and must be reviewed against source documents.
Infrastructure and storage
- Dev deployment uses isolated SaaS, Marketing, worker, Postgres pgvector, and object storage services.
- Signed upload and view flows avoid exposing raw storage keys to the browser.
- Database migrations run before the SaaS app starts.
- Worker queues and retry controls support document ingestion resilience.
Compliance evidence
- Sensitive write paths are designed to produce audit evidence.
- Deletion workflows track request, review, purge, actor, and retention context.
- Billing state, usage, and failed-payment controls are organization-scoped.
- Operational runbooks and retained evidence support release review.
Built for reviewable agent assistance
AgentAssist is designed to help agents find, summarize, compare, and explain approved source documents. It is not a replacement for professional advice, source approval, human review, or compliance review.
- Source-grounded summaries and comparisons should cite the documents used.
- No-context and no-advice rules prevent the copilot from pretending to know facts that are not in the workspace.
- Prompt-injection checks are intended to protect hidden instructions, tenant data, and credentials.
- Structured artifacts remain reviewable before they are exported, shared, or saved as reusable facts.