Trust Center

Agentrix — Mengel Enterprises LLC

Last Updated: September 18, 2026


How we think about security

On Agentrix, you build your own agents: their instructions, tools, connectors, custom code and data sources. We secure the platform they run on, so that the guarantees below hold even when an agent is misconfigured or a user is hostile. You control how your agents use the access you give them.

Customer data is stored in Microsoft Azure regions in the United States. We do not use your prompts, agent configurations, inputs, outputs or knowledge to train AI models, ours or anyone else's.

Compliance status

We state our status plainly. If a certification is not listed as held, we do not hold it.

SOC 2 Type II

Readiness in progress

We are preparing for a SOC 2 Type II audit. No audit has started and we do not hold a SOC 2 report. We can share our control documentation under NDA.

ISO/IEC 27001

Gap assessment complete

Our controls are designed against ISO/IEC 27001:2022 Annex A. We are not certified.

ISO/IEC 42001 and NIST AI RMF

Controls aligned

Agent governance (versioning, approvals, risk tiers, inventory export) is designed against ISO/IEC 42001 and the NIST AI Risk Management Framework. We are not certified.

HIPAA

Available on request (Enterprise)

Agentrix runs under the same HIPAA program as the rest of our platform: a data store with customer-managed encryption keys, private network access only and point-in-time restore; Microsoft's HIPAA Business Associate Agreement for the Azure services that hold or process your data; HIPAA-mode organizations limited to GPT models on our Azure OpenAI deployment, with field-level encryption of run content and agent memories. Enterprise customers can request a Business Associate Agreement. Until it is signed and HIPAA mode is on for your organization, do not send protected health information to Agentrix.

GDPR and CCPA

DPA available

We act as your processor or service provider under a Data Processing Addendum.

Security controls

Tenant isolation

Each organization's agents, runs, memories, knowledge, keys and audit trail are stored in and read from that organization's own partition, derived from the signed-in identity. Regression tests and a repository-wide check block any change that reads outside it.

Agents can only use the tools you give them

A model that asks for a tool it was not offered is refused. Tools that need approval wait for a human, whether called from chat or a workflow. Changes to an MCP tool definition disable the tool until you re-approve it.

Defenses against prompt injection

Tool results, web pages, documents and memories are marked as untrusted data with tamper-resistant boundaries. They are screened for injection attempts, and side-effecting actions can require human approval. These controls reduce the risk; they do not eliminate it, which is why your agent design matters too.

Identity and access

Role-based access with built-in roles (Owner, Admin, Builder, Operator, Viewer, Auditor). Organization-enforced MFA, session limits and IP allowlists. Single sign-on (OpenID Connect) and SCIM provisioning on Enterprise. API keys are hashed, scoped, expiring and rotatable.

Tamper-evident audit trail

Security-relevant actions, including any Agentrix staff access to your organization, are written to an append-only, hash-chained audit trail. You can export it, verify the chain, and stream it to your SIEM.

Secrets and encryption

Connector and platform credentials live in Azure Key Vault. Data is encrypted in transit (TLS 1.2+) and at rest. Credentials are scrubbed from run records and logs before storage.

Sandboxed custom code

Custom code runs in an isolated, short-lived container per run, with no platform identity and no inbound network access. It needs two-person approval before it runs.

Secure development and operations

Every release is blocked on new high or critical findings from dependency scanning, static analysis, secret scanning and (for the API) container image scanning. Security-sensitive code requires owner review. We rate-limit sign-in and agent runs, and run cloud threat detection.

Shared responsibility for the agents you build

Agentrix is responsible for the security of the platform. That covers tenant isolation, the tool and approval boundaries, the safety floor, credential storage, the audit trail, the custom-code sandbox, and the infrastructure.

You are responsible for what your agents do with the access you give them. That covers:

  • their instructions, and which model they use;
  • which tools, connectors and data they can reach;
  • requiring approval for irreversible actions;
  • protecting the API keys and credentials you create;
  • having the right to process the data you connect; and
  • telling your end users when they are talking to AI.

Content your agents read can contain hidden instructions, from web pages, emails or documents. We mark and screen that content, but give an agent that reads untrusted content no way to send data out or change things without your approval.

The full responsibility matrix is available on request, and your agreement includes our Acceptable Use Policy.

Subprocessors

Third parties that process customer data on our behalf:

ProviderPurposeScope
Microsoft AzureHosting, database, storage, Key Vault, cache, content delivery, sandbox containers, monitoring, transactional emailAll customers
Microsoft Azure OpenAI / AI FoundryAI model inference and embeddingsAll customers
Microsoft Azure AI Content SafetyModeration and prompt-injection screeningAll customers
AnthropicClaude model inferenceServed through Microsoft Foundry when an agent uses a Claude model. Never used in HIPAA mode.
TavilyWeb search toolOnly when your agent uses web search
StripeBilling and paymentsNo agent content
PayPalAlternative checkoutNo agent content

Services you connect to your agents yourself (for example Google Workspace, Microsoft 365, your CRM or an MCP server) receive data at your direction. They are your vendors, not our subprocessors. We give at least 30 days' notice before adding a subprocessor that processes customer data.

DPA, BAA and security documentation

  • Data Processing Addendum: available to every paid customer.
  • Business Associate Agreement: coming soon for Enterprise customers, once it completes legal review.
  • Security documentation: our control matrix, shared responsibility model and questionnaire answers, shared under NDA.

Request any of these at legal@agentrix.studio.

Vulnerability disclosure

If you believe you have found a security vulnerability in Agentrix, please report it privately to security@agentrix.studio. Our contact details are also published in /.well-known/security.txt.

  • We aim to acknowledge reports within 3 business days and to give an initial assessment within 10.
  • Test only with accounts and organizations you own. Do not access other customers' data, degrade the service, or run agents that consume resources at scale.
  • In scope: the Agentrix web app and API. This includes cross-organization access, sandbox escape, calling a tool that was not offered, and bypassing an approval gate.
  • We will not pursue legal action against good-faith research that follows these rules.
  • Give us reasonable time to fix an issue before disclosing it; 90 days by default, and we will agree on a date with you.

Contact

Mengel Enterprises LLC — Agentrix
Security: security@agentrix.studio
Privacy: privacy@agentrix.studio
Legal and contracts: legal@agentrix.studio