Security Policy
Last updated: July 2026
1. Overview
Agentrion Pte. Ltd. (“Agentrion”) is committed to maintaining the highest standards of information security. This policy outlines our approach to safeguarding customer data and ensuring platform integrity in compliance with Singapore’s Cybersecurity Act 2018 and the Personal Data Protection Act 2012 (“PDPA”).
2. Certifications & Compliance
- SOC 2 Type II certified (annual audit)
- ISO 27001:2022 certified Information Security Management System
- CSA STAR Level 2 attestation
- Compliant with Singapore PDPA, GDPR, and Thailand PDPA
- MAS Technology Risk Management (TRM) Guidelines aligned
- IMDA Data Protection Trustmark eligible
3. Data Encryption
All data is encrypted in transit using TLS 1.3. Data at rest is encrypted with AES-256. Encryption keys are managed through a dedicated Key Management Service (KMS) with hardware security module (HSM) backing, hosted within Singapore-based data centres.
4. Infrastructure & Data Residency
Our primary infrastructure is hosted in Singapore with optional data residency in Tokyo, Sydney, and Hong Kong. Customer data never leaves the designated region without explicit written consent. All hosting providers are MAS-outsourcing-compliant and CSA-certified.
5. Access Control
- Role-Based Access Control (RBAC) across all platform layers
- Multi-Factor Authentication (MFA) enforced for all internal access
- Just-in-time privileged access with automatic expiry
- Quarterly access reviews and recertification
- SSO integration via SAML 2.0 and OIDC
6. Vulnerability Management
We conduct continuous automated vulnerability scanning, annual penetration testing by independent third parties, and participate in a responsible disclosure programme. Critical vulnerabilities are patched within 24 hours; high-severity within 72 hours.
7. Incident Response
Our incident response plan follows NIST SP 800-61 guidelines. In accordance with the PDPA, notifiable data breaches are reported to the Personal Data Protection Commission (PDPC) and affected individuals within 3 calendar days of assessment. Customers are notified within 72 hours as required under contractual SLAs.
8. Business Continuity & Disaster Recovery
RPO (Recovery Point Objective): 1 hour. RTO (Recovery Time Objective): 4 hours. Multi-AZ deployment with automated failover. Annual BCP/DR drills conducted and documented. Compliant with SS 540:2008 (Singapore Standard for Business Continuity Management).
9. Employee Security
- Background checks for all employees with access to customer data
- Annual security awareness training and phishing simulations
- Confidentiality and non-disclosure agreements
- Clean desk policy and secure device management
10. Third-Party Risk Management
All sub-processors and vendors undergo security assessments before onboarding. We maintain a register of sub-processors available upon request. Vendors are contractually bound to equivalent security and data protection standards.
11. Contact
For security concerns or to report a vulnerability, contact our Security Team at security@agentrion.ai. Our PGP key is available on request.