Security
Security and control, stated plainly.
What an oktogonAI agent can touch, what it needs a person for and what it can never do. And, just as plainly, what we do not claim.
Deployment model
The agents run inside your infrastructure.
Each solution is deployed into your own environment and works against the systems your data already lives in: your ERP, CRM, mailboxes and document storage. It is not a shared service your records are copied into. The model endpoints each agent calls, and the data terms that apply to them, are agreed with you before deployment.
Your infrastructure
Deployed into the same environment as the systems it works with.
Model endpoint
Where it runs, and its data terms, agreed with you before deployment
The control layer
Four controls, in every deployment.
Scoped permissions
Each agent reads and writes only what its workflow needs. Permissions are set at deployment and enforced at runtime.
Approval rules
You decide what executes on its own, what needs a person's approval and what always goes to an employee.
Exception handling
Anything outside the rules is stopped and handed to a person with the reason attached. It is never guessed.
Activity log
Every action an agent takes is written to a log inside your environment.
In practice
One agent's permissions, written down.
The Quote Agent, in an example configuration: the same grant shown on the homepage. Every solution page lists its own.
Can
- Read incoming requests
- Access product data
- Check customer pricing
- Prepare quotes
- Update CRM
Needs approval
- Quotes above $50,000
- Discounts above 5%
Cannot
- Change master pricing
- Delete records
Segregation of duties
Where money moves, a person decides.
In finance workflows the agent prepares, matches and posts. It never approves its own postings and never releases a payment, and a change to supplier bank details stops the document whatever its value.
See the Finance AgentCompliance
What we claim, and what we don't.
- Designed around
- GDPR and EU AI Act requirements
- Not held
- SOC 2, ISO 27001, HIPAA
GDPR and the EU AI Act are design inputs, not attestations. oktogonAI does not currently hold SOC 2, ISO 27001 or HIPAA certification, and this page will say so until a certificate exists.
Models and partners
Model choice per workflow.
Use the right model for the right workflow without locking operations to one provider.
- AnthropicClaude models
- OpenAIGPT models
- MicrosoftBusiness applications
- SalesforceCRM platform
- HubSpotCRM and marketing
oktogonAI is a member of the partner programs above. Partner status covers the platforms oktogonAI builds on and integrates with; it does not mean any of these companies endorses a specific deployment.
This website
No cookies. No third-party requests.
This site sets no cookies, uses no browser storage and loads nothing from other domains. Fonts and images are served from our own. If analytics is switched on, it is Plausible, which is cookieless and stores no personal data.
Questions
Security questions, answered plainly.
Where do the agents run?
Inside your own infrastructure, against the systems your data already lives in. The model endpoints they call, and the data terms that apply to them, are agreed with you before deployment.
Can an agent do something it was not configured to do?
No. Permissions are scoped at deployment and enforced at runtime; an action outside them is not available to the agent.
What happens when an agent is unsure?
It stops and hands the case to a person with the reason attached. The threshold (confidence, value, customer, action type) is configured with you.
Is every action logged?
Yes. Every action an agent takes is written to an activity log inside your environment.
Do you hold SOC 2 or ISO 27001 certification?
No. oktogonAI does not currently hold SOC 2, ISO 27001 or HIPAA certification. Deployments are designed around GDPR and EU AI Act requirements, which we describe as design inputs rather than attestations.
Bring your security questions to the review.
The review session covers integration requirements and where the agent sits in your environment. It is the right place to put your checklist on the table.
Start with one workflow
Fixed scope for the first workflow, agreed before we start. Expansion is your decision once it proves value.
How it worksStart with quotes or orders
Two primary workflows first. Procurement, finance and customer operations once the first one proves value.
See the solutions