Security and Compliance
Last updated: July 2026
1. Where your data lives
Client data on The Agency dashboard is stored in UK-resident managed databases, on infrastructure dedicated to this platform and separated from any other product we run. Data is encrypted in transit and at rest, and staging and production environments use separate databases so test work never touches live client data.
2. How access is controlled
- • Server-side authorisation on every request: access is checked against the live database each time, never trusted from the browser.
- • Role-based access: clients see only their own workspace; our team members see only what their role allows.
- • Two-factor authentication: every administrator account requires an authenticator app code on top of its password, with single-use backup codes stored only as hashes.
- • Instant revocation: we can invalidate any account's sessions immediately, and disabled accounts lose access on their very next request.
- • Hardened sessions: sign-in cookies use current browser protections (secure, host-locked, inaccessible to page scripts) and rate limiting slows any password-guessing attempt.
3. What we record
We keep a full audit trail of account activity: sign-ins, two-factor events, administrative actions, and any occasion a team member views a client workspace on the client's behalf. Agreement signatures are recorded with the signer, the time, and a fingerprint of the exact document version signed. Audit records are kept so that questions like "who accessed what, and when" always have an answer.
4. AI transparency
Your AI team is always presented as what it is. AI assistants are labelled as AI when you or your customers interact with them, and work produced by your agents is identifiable as AI work, in line with the transparency obligations of the EU AI Act. We never pass an AI assistant off as a human.
5. Your rights
We operate under UK GDPR. You may request a full export of your data, or its deletion, at any time; we complete these requests within 5 business days. Our privacy policy covers the detail of what we collect and why, and you can raise any concern with the Information Commissioner's Office at ico.org.uk.
6. Who we build on
We run on a short list of vetted infrastructure providers covering hosting, managed databases, AI models and CRM. The current list, and where each provider stores data, is available on request at hello@theagency.io.
7. Questions
Security questions, disclosure reports, or anything a security reviewer needs before signing: email hello@theagency.io and we will respond within 2 business days.