Public BetaJoin as a Founding User and lock in 50% off while the offer is active. Register and create AI agents

Trust & Security

Trust, privacy, and security for AI agent infrastructure

Last updated: June 21, 2025

KlicForge maintains a privacy compliance readiness programme aligned to GDPR, CCPA/CPRA, and Singapore PDPA. This includes documented data inventory, retention practices, data subject request workflows, subprocessors, and technical safeguards.

Compliance posture

KlicForge is designed and operated with privacy and data protection controls aligned to GDPR, CCPA/CPRA, and Singapore PDPA requirements.

GDPR-alignedCCPA/CPRA-alignedSingapore PDPA-aligned

This is not a certification. It describes KlicForge's implemented privacy readiness controls and supporting documentation.

Privacy controls

Technical and operational controls that protect personal data across the platform.

Tenant isolation

All data is strictly scoped by tenant. Cross-tenant data access is architecturally prohibited at the database query level.

Encryption at rest

Sensitive fields — including contact PII, channel credentials, TOTP secrets, and integration tokens — are encrypted with AES-256-GCM using per-environment keys.

Encryption in transit

All traffic is served over TLS. Database connections use TLS. API traffic is proxied through Cloudflare.

PII redaction in guardrails

The agent runtime includes a PII redaction guardrail that masks emails, phone numbers, credit card patterns, and government ID formats before they appear in agent responses.

Data subject request workflows

KlicForge operates a documented DSAR workflow supporting access, export, correction, deletion, and consent withdrawal requests with defined SLAs.

Retention enforcement

Conversations expire automatically based on per-channel TTLs. Tenant deletion triggers hard erasure of PII across all stores. Audit logs are retained for 12–24 months.

Security controls

Infrastructure and operational security measures in place across the platform.

Multi-factor authentication

TOTP-based MFA is available to all users. Administrative access requires MFA to be verified for every session.

Role-based access control

System roles (superadmin, forgeadmin) and tenant roles (owner, admin, member) enforce least-privilege access at every layer.

Audit logging

Security-relevant events — MFA changes, admin actions, privacy request handling — are recorded in an append-only audit log.

Secrets management

Secrets are injected via GitHub Actions secrets at deploy time. No secrets are stored in application bundles, source code, or logs.

Incident response

A documented incident response policy defines SEV-1/2/3 severity levels, roles, containment steps, and notification timelines aligned to GDPR (72h), CCPA (30d), and PDPA (3d).

Security scanning

OWASP ZAP baseline and API scans are run against staging on each release. Findings are triaged before production deployment.

AI-specific safeguards

Controls specific to the AI agent runtime that limit risk from prompt injection, capability abuse, and unintended data exposure.

Prompt injection detection

The agent runtime actively checks user messages, knowledge content, and tool outputs for prompt injection patterns and blocks high-severity attempts.

Secret leak protection

A guardrail scans agent outputs for secrets and credential patterns before they reach the end user.

Tool allowlist enforcement

Each agent's tool access is explicitly configured. Agents can only invoke tools they are authorised for. Capability boundary enforcement prevents scope creep.

AI provider subprocessors

KlicForge routes model requests through a provider gateway. Each AI provider is disclosed on the Subprocessors page, including their data retention and model training policies.

Grounded answer mode

Agents can be configured to only answer from their knowledge base, reducing hallucination risk and limiting what data is included in model requests.

Subprocessors

KlicForge uses subprocessors to provide hosting, AI model access, payments, communications, and infrastructure services. Each subprocessor is disclosed with its purpose, data categories, processing regions, and DPA availability.

View Subprocessor List →

Data rights

Depending on your jurisdiction, you may have the right to access, correct, delete, export, or restrict the processing of your personal data. KlicForge supports:

  • Data access requests (GDPR Art. 15, CCPA, PDPA)
  • Data export / portability requests
  • Data correction requests
  • Data deletion requests (right to erasure)
  • Consent withdrawal
  • CCPA Do Not Sell or Share requests

Response times: 30 days for most requests, 15 business days for CCPA opt-out.

Contact

Questions about privacy, security, or compliance? Contact us at privacy@klicforge.ai. For vendor procurement reviews, our Privacy Policy, DPA, Subprocessor List, and Security Overview are available above.