Trust & Security
Trust, privacy, and security for AI agent infrastructure
Last updated: June 21, 2025
KlicForge maintains a privacy compliance readiness programme aligned to GDPR, CCPA/CPRA, and Singapore PDPA. This includes documented data inventory, retention practices, data subject request workflows, subprocessors, and technical safeguards.
Compliance posture
KlicForge is designed and operated with privacy and data protection controls aligned to GDPR, CCPA/CPRA, and Singapore PDPA requirements.
This is not a certification. It describes KlicForge's implemented privacy readiness controls and supporting documentation.
Privacy controls
Technical and operational controls that protect personal data across the platform.
Tenant isolation
All data is strictly scoped by tenant. Cross-tenant data access is architecturally prohibited at the database query level.
Encryption at rest
Sensitive fields — including contact PII, channel credentials, TOTP secrets, and integration tokens — are encrypted with AES-256-GCM using per-environment keys.
Encryption in transit
All traffic is served over TLS. Database connections use TLS. API traffic is proxied through Cloudflare.
PII redaction in guardrails
The agent runtime includes a PII redaction guardrail that masks emails, phone numbers, credit card patterns, and government ID formats before they appear in agent responses.
Data subject request workflows
KlicForge operates a documented DSAR workflow supporting access, export, correction, deletion, and consent withdrawal requests with defined SLAs.
Retention enforcement
Conversations expire automatically based on per-channel TTLs. Tenant deletion triggers hard erasure of PII across all stores. Audit logs are retained for 12–24 months.
Security controls
Infrastructure and operational security measures in place across the platform.
Multi-factor authentication
TOTP-based MFA is available to all users. Administrative access requires MFA to be verified for every session.
Role-based access control
System roles (superadmin, forgeadmin) and tenant roles (owner, admin, member) enforce least-privilege access at every layer.
Audit logging
Security-relevant events — MFA changes, admin actions, privacy request handling — are recorded in an append-only audit log.
Secrets management
Secrets are injected via GitHub Actions secrets at deploy time. No secrets are stored in application bundles, source code, or logs.
Incident response
A documented incident response policy defines SEV-1/2/3 severity levels, roles, containment steps, and notification timelines aligned to GDPR (72h), CCPA (30d), and PDPA (3d).
Security scanning
OWASP ZAP baseline and API scans are run against staging on each release. Findings are triaged before production deployment.
AI-specific safeguards
Controls specific to the AI agent runtime that limit risk from prompt injection, capability abuse, and unintended data exposure.
Prompt injection detection
The agent runtime actively checks user messages, knowledge content, and tool outputs for prompt injection patterns and blocks high-severity attempts.
Secret leak protection
A guardrail scans agent outputs for secrets and credential patterns before they reach the end user.
Tool allowlist enforcement
Each agent's tool access is explicitly configured. Agents can only invoke tools they are authorised for. Capability boundary enforcement prevents scope creep.
AI provider subprocessors
KlicForge routes model requests through a provider gateway. Each AI provider is disclosed on the Subprocessors page, including their data retention and model training policies.
Grounded answer mode
Agents can be configured to only answer from their knowledge base, reducing hallucination risk and limiting what data is included in model requests.
Subprocessors
KlicForge uses subprocessors to provide hosting, AI model access, payments, communications, and infrastructure services. Each subprocessor is disclosed with its purpose, data categories, processing regions, and DPA availability.
View Subprocessor List →Data rights
Depending on your jurisdiction, you may have the right to access, correct, delete, export, or restrict the processing of your personal data. KlicForge supports:
- Data access requests (GDPR Art. 15, CCPA, PDPA)
- Data export / portability requests
- Data correction requests
- Data deletion requests (right to erasure)
- Consent withdrawal
- CCPA Do Not Sell or Share requests
Response times: 30 days for most requests, 15 business days for CCPA opt-out.
Contact
Questions about privacy, security, or compliance? Contact us at privacy@klicforge.ai. For vendor procurement reviews, our Privacy Policy, DPA, Subprocessor List, and Security Overview are available above.