Security

Trust must survive retries, revocation and recovery.

agiHx stops rather than guesses when identity, authority or organisation ownership is unclear. The controls below explain the implemented design; complete production evidence is still in development.

Control model

Layered, testable boundaries

In development

Organisation isolation

Every request is tied to one organisation, with database rules preventing access to another organisation's records.

Bounded instructions

Work stops when the agent's instructions are missing, changed, expired, revoked or outside the allowed scope.

Duplicate protection

Retries, approvals and email events carry durable duplicate protection so the same action is not applied twice.

Evidence that shows changes

Signed event history and portable receipts reveal if completed evidence has been changed or substituted.

Provider independence

Email delivery stays behind the agiHx API, so changing a delivery provider does not change customer identities or records.

Recovery

Version history, backups, failed-work recovery and exact-release rollback are tested as part of release evidence.

Report a vulnerability

Contact the security owner directly.

Send a minimal description and a safe way to reproduce the issue. Do not include credentials, raw customer email or personal data.

Email info@agihx.com