Public BetaJoin as a Founding User and lock in 50% off while the offer is active. Register and create AI agents

Trust & Security

Trust, privacy, and security for AI agent infrastructure

Last updated: June 18, 2026

KlicForge maintains a privacy compliance readiness programme aligned to GDPR, CCPA/CPRA, and Singapore PDPA. This includes documented data inventory, retention practices, data subject request workflows, subprocessors, and technical safeguards.

Compliance, Assurance & AI Governance

Compliance status last reviewed: September 14, 2026

Privacy & Data Protection

GDPR

Aligned

European Union / EEA privacy and data protection readiness.

CCPA / CPRA

Aligned

California privacy rights and consumer data protection readiness.

PDPA

Aligned

Singapore Personal Data Protection Act readiness.

Security & Assurance

SOC 2 Type II

Readiness underway

AICPA Trust Services Criteria readiness — no independent audit engaged yet.

ISO 27001

Readiness underway

Information security management system controls mapped to ISO/IEC 27001:2022 — no accredited audit yet.

Responsible AI

ISO 42001

Implementation underway

AI management system for responsible governance and continual improvement of AI. Not yet audited or certified.

ISO/IEC 42005

Planned

Structured AI impact assessment across the AI system lifecycle.

Status reflects KlicForge's current controls, readiness activities and assurance standing. “Aligned” does not represent third-party certification. Certifications and attestations are identified explicitly where applicable. Adoption of a Responsible AI framework does not itself imply certification.

AI governance (ISO/IEC 42001)

KlicForge does not only use AI — it provides the infrastructure other organisations use to deploy AI systems. We maintain an AI system register, AI risk register, documented impact-assessment and lifecycle procedures, and AI-specific supplier records covering model providers, their data-retention posture, and whether they train on customer data. None of ours do.

A daily automated job verifies a subset of these controls against the running platform rather than against a checklist, and a control whose check does not pass stops counting as evidenced.

KlicForge is not certified to ISO/IEC 42001. This is a self-assessed readiness programme: governance documents are drafted and awaiting review, control mappings await verification against the licensed standard, and no independent audit has been performed. We will say so plainly here if and when that changes.

Singapore PDPA

For Singapore organisations, we publish a dedicated page covering KlicForge's role as a data intermediary under the PDPA, responsibilities, data location, AI provider handling, breach allocation, and a management/DPO FAQ — plus a one-page overview your DPO can review or print.

Data residency: application compute and the primary database run in DigitalOcean's Singapore region (SGP1). Providers that operate globally are disclosed per subprocessor.

Privacy controls

Technical and operational controls that protect personal data across the platform.

Tenant isolation

All data is strictly scoped by tenant. Cross-tenant data access is architecturally prohibited at the database query level.

Encryption at rest

Sensitive fields — including contact PII, channel credentials, TOTP secrets, and integration tokens — are encrypted with AES-256-GCM using per-environment keys.

Encryption in transit

All traffic is served over TLS. Database connections use TLS. API traffic is proxied through Cloudflare.

PII redaction in guardrails

A default-on, per-agent-configurable guardrail masks emails, phone numbers, card numbers, and US SSN patterns in user messages before they are sent to AI models. Raw channel identifiers (Telegram IDs, WhatsApp numbers) are never included in model requests.

Data subject request workflows

KlicForge operates a documented DSAR workflow supporting access, export, correction, deletion, and consent withdrawal requests with defined SLAs.

Retention enforcement

Conversations expire automatically based on per-channel TTLs. Tenant deletion triggers hard erasure of PII across all stores. Audit logs are retained for 12–24 months.

Security controls

Infrastructure and operational security measures in place across the platform.

Multi-factor authentication

TOTP-based MFA is available to all users. Administrative access requires MFA to be verified for every session.

Role-based access control

System roles (superadmin, forgeadmin) and tenant roles (owner, admin, member) enforce least-privilege access at every layer.

Audit logging

Security-relevant events — MFA changes, admin actions, privacy request handling — are recorded in an append-only audit log.

Secrets management

Secrets are injected via GitHub Actions secrets at deploy time. No secrets are stored in application bundles, source code, or logs.

Incident response

A documented incident response policy defines SEV-1/2/3 severity levels, roles, containment steps, and notification timelines aligned to GDPR (72h), CCPA (30d), and PDPA (3d).

Security scanning

OWASP ZAP baseline and API scans run against staging nightly and on each release, plus authenticated scans of staging. Findings are triaged before production deployment.

AI-specific safeguards

Controls specific to the AI agent runtime that limit risk from prompt injection, capability abuse, and unintended data exposure.

Prompt injection detection

The agent runtime actively checks user messages, knowledge content, and tool outputs for prompt injection patterns and blocks high-severity attempts.

Secret leak protection

A guardrail scans agent outputs for secrets and credential patterns before they reach the end user.

Tool allowlist enforcement

Each agent's tool access is explicitly configured. Agents can only invoke tools they are authorised for. Capability boundary enforcement prevents scope creep.

AI provider subprocessors

KlicForge routes model requests through a provider gateway. Each AI provider is disclosed on the Subprocessors page, including their data retention and model training policies.

Grounded answer mode

Agents can be configured to only answer from their knowledge base, reducing hallucination risk and limiting what data is included in model requests.

Subprocessors

KlicForge uses subprocessors to provide hosting, AI model access, payments, communications, and infrastructure services. Each subprocessor is disclosed with its purpose, data categories, processing regions, and DPA availability.

View Subprocessor List →

Data rights

Depending on your jurisdiction, you may have the right to access, correct, delete, export, or restrict the processing of your personal data. KlicForge supports:

  • Data access requests (GDPR Art. 15, CCPA, PDPA)
  • Data export / portability requests
  • Data correction requests
  • Data deletion requests (right to erasure)
  • Consent withdrawal
  • CCPA Do Not Sell or Share requests

Response times: 30 days for most requests, 15 business days for CCPA opt-out.

Contact

Questions about privacy, security, or compliance? Contact us at privacy@klicforge.ai. For vendor procurement reviews, our Privacy Policy, DPA, and Subprocessor List are available above. A security overview is available on request.