Skip to content

Security

Security and control, stated plainly.

What an oktogonAI agent can touch, what it needs a person for and what it can never do. And, just as plainly, what we do not claim.

Deployment model

The agents run inside your infrastructure.

Each solution is deployed into your own environment and works against the systems your data already lives in: your ERP, CRM, mailboxes and document storage. It is not a shared service your records are copied into. The model endpoints each agent calls, and the data terms that apply to them, are agreed with you before deployment.

Your infrastructure

ERP
CRM
Mailboxes
Documents
oktogonAI agent
Activity logevery action

Deployed into the same environment as the systems it works with.

Model endpoint

Where it runs, and its data terms, agreed with you before deployment

The control layer

Four controls, in every deployment.

Scoped permissions

Each agent reads and writes only what its workflow needs. Permissions are set at deployment and enforced at runtime.

Approval rules

You decide what executes on its own, what needs a person's approval and what always goes to an employee.

Exception handling

Anything outside the rules is stopped and handed to a person with the reason attached. It is never guessed.

Activity log

Every action an agent takes is written to a log inside your environment.

In practice

One agent's permissions, written down.

The Quote Agent, in an example configuration: the same grant shown on the homepage. Every solution page lists its own.

Quote Agent permissions
scoped

Can

  • Read incoming requests
  • Access product data
  • Check customer pricing
  • Prepare quotes
  • Update CRM

Needs approval

  • Quotes above $50,000
  • Discounts above 5%

Cannot

  • Change master pricing
  • Delete records

Segregation of duties

Where money moves, a person decides.

In finance workflows the agent prepares, matches and posts. It never approves its own postings and never releases a payment, and a change to supplier bank details stops the document whatever its value.

See the Finance Agent

Compliance

What we claim, and what we don't.

Designed around
GDPR and EU AI Act requirements
Not held
SOC 2, ISO 27001, HIPAA

GDPR and the EU AI Act are design inputs, not attestations. oktogonAI does not currently hold SOC 2, ISO 27001 or HIPAA certification, and this page will say so until a certificate exists.

Models and partners

Model choice per workflow.

Use the right model for the right workflow without locking operations to one provider.

  • AnthropicClaude models
  • OpenAIGPT models
  • MicrosoftBusiness applications
  • SalesforceCRM platform
  • HubSpotCRM and marketing

oktogonAI is a member of the partner programs above. Partner status covers the platforms oktogonAI builds on and integrates with; it does not mean any of these companies endorses a specific deployment.

This website

No cookies. No third-party requests.

This site sets no cookies, uses no browser storage and loads nothing from other domains. Fonts and images are served from our own. If analytics is switched on, it is Plausible, which is cookieless and stores no personal data.

Questions

Security questions, answered plainly.

Where do the agents run?

Inside your own infrastructure, against the systems your data already lives in. The model endpoints they call, and the data terms that apply to them, are agreed with you before deployment.

Can an agent do something it was not configured to do?

No. Permissions are scoped at deployment and enforced at runtime; an action outside them is not available to the agent.

What happens when an agent is unsure?

It stops and hands the case to a person with the reason attached. The threshold (confidence, value, customer, action type) is configured with you.

Is every action logged?

Yes. Every action an agent takes is written to an activity log inside your environment.

Do you hold SOC 2 or ISO 27001 certification?

No. oktogonAI does not currently hold SOC 2, ISO 27001 or HIPAA certification. Deployments are designed around GDPR and EU AI Act requirements, which we describe as design inputs rather than attestations.

Bring your security questions to the review.

The review session covers integration requirements and where the agent sits in your environment. It is the right place to put your checklist on the table.

Start with one workflow

Fixed scope for the first workflow, agreed before we start. Expansion is your decision once it proves value.

How it works

Start with quotes or orders

Two primary workflows first. Procurement, finance and customer operations once the first one proves value.

See the solutions