Ayoopa

Home / Security

Security & trust

An agent that can act is an agent that can be attacked.

Giving software the ability to read your systems and change records raises the stakes on every control around it. Ayoopa is built so that the security answer is a configuration, not an exception.

Encryption

TLS 1.2+ in transit, AES-256 at rest, with customer-managed keys available on Enterprise. Credentials are stored in your vault, not ours.

Access control

SAML and OIDC SSO, SCIM provisioning, scoped service accounts and per-agent permissions. Least privilege is the default, not an option.

Auditability

An immutable record of prompts, tool calls, approvals and configuration changes, exportable to your SIEM or storage on a schedule you control.

Deployment isolation

Run in your own cloud account, on-premise or in an air-gapped network. Workloads are isolated per workspace with no shared execution path.

Data handling

Regional residency, configurable retention, PII redaction before logs are written, and a contractual guarantee that your data never trains a model.

Operations

Independent penetration tests, a documented incident response process, and a security contact that answers. Status and advisories published to customers.

Controls

The summary security teams ask for first.

AreaControl
CertificationSOC 2 Type II, audited annually by an independent firm. Report available under NDA.
EncryptionTLS 1.2+ in transit; AES-256 at rest; optional customer-managed keys.
AuthenticationSAML 2.0 and OIDC SSO, SCIM 2.0 provisioning, enforced MFA for local accounts.
AuthorizationRole-based access control, per-agent scopes, approval gates on sensitive actions.
LoggingImmutable audit trail, configurable retention, scheduled export, SIEM integration.
ResidencyUS, EU or your own infrastructure. Data stays in the region you select.
Model trainingCustomer data is never used to train or fine-tune models, by Ayoopa or its providers.
TestingAnnual third-party penetration test and continuous dependency scanning.

Disclosure

Reporting a vulnerability.

We welcome reports from security researchers. Send a description and, where possible, a reproduction to the address below. We aim to acknowledge within two business days and will keep you updated through remediation.

Please do not test against customer workspaces, run denial-of-service tests, or access data that is not yours.

security@ayoopa.com

Procurement

What we can send your reviewers.

  • SOC 2 Type II report under NDA
  • Completed CAIQ / SIG Lite questionnaire
  • Data processing addendum and sub-processor list
  • Penetration test summary letter
  • Architecture and data-flow documentation
  • Business continuity and disaster recovery plan

Request the security pack