Security and Compliance
Last updated: July 2026
1. Where your data lives
Client data on The Agency dashboard is stored in UK-resident managed databases. They run on infrastructure dedicated to this platform, kept separate from any other product we run. Data is encrypted in transit and at rest, and staging and production environments use separate databases so test work never touches live client data.
2. How access is controlled
- • Server-side authorisation on every request: access is checked against the live database each time, never trusted from the browser.
- • Role-based access: clients see only their own workspace; our team members see only what their role allows.
- • Two-factor authentication: every administrator account requires an authenticator app code on top of its password, with single-use backup codes stored only as hashes.
- • Instant revocation: we can invalidate any account's sessions immediately, and disabled accounts lose access on their very next request.
- • Hardened sessions: sign-in cookies use current browser protections (secure, host-locked, inaccessible to page scripts) and rate limiting slows any password-guessing attempt.
3. What we record
We keep a full audit trail of account activity: sign-ins, two-factor events, administrative actions, and any occasion a team member views a client workspace on the client's behalf. Agreement signatures are recorded with the signer, the time, and a fingerprint of the exact document version signed. Audit records are kept so that questions like "who accessed what, and when" always have an answer.
4. AI transparency
Your AI team is always presented as what it is. AI assistants are labelled as AI when you or your customers interact with them. Work produced by your agents is identifiable as AI work, in line with the transparency obligations of the EU AI Act. We never pass an AI assistant off as a human.
5. Your rights
We operate under UK GDPR. You may request a full export of your data, or its deletion, at any time; we complete these requests within 5 business days. Our privacy policy covers the detail of what we collect and why, and you can raise any concern with the Information Commissioner's Office at ico.org.uk.
6. Who we build on
We run on a short list of vetted infrastructure providers covering hosting, managed databases, AI models and CRM. The current list, and where each provider stores data, is available on request at hello@theagency.io.
7. Questions
Security questions, disclosure reports, or anything a security reviewer needs before signing: email hello@theagency.io and we will respond within 2 business days.
No access needed
An audit that starts with one address
We only need your website address and a few answers, then we check what the AIs say about your business.
Related
- AI vendor lock-in: do you own your data?How to check a contract and stay in control of your data and your systems.
- What happens to your AI system if you cancel?What happens to your data, your website and your automations if you leave.
- AI COO that runs your operationsYour pipeline, follow-up and numbers on one page, run for you.