Security

Data Security

We take data safety seriously at Agentsy. Read on below for how we keep your data, documents and business information safe and secure.

LAST UPDATED 6 JULY 2026

How We Keep Your Data Safe at Agentsy

At Agentsy we take data safety and security seriously - in fact it's one of the driving forces behind why we built our platform and position it as the one, central place for your team to use AI at work.

Multiple recent studies have found that around 50% of employees use unauthorised AI tools at work - tools your business has no oversight of, and no assurance that submitted data is protected. We take the opposite approach, selecting each element of our technology stack to ensure your company information is respected and protected.

We also let your business set guardrails - like your company's tone of voice and agent-specific knowledge bases - so content generated by our agents sounds like you and is grounded in your own policies, procedures and knowledge.

Below is a high-level overview of the key components of our technology as they relate to data safety and security. If you'd like more detail - for a security review or procurement process - just ask; we're happy to go deeper.

AI Models

We access AI models exclusively through their paid, business-grade API services - never their free consumer products - because the API tiers come with contractual terms that protect your data. The core protection: data submitted through these APIs is not used to train the providers' foundation models.

We currently work with several leading providers, each used for a specific purpose:

  • Anthropic (Claude) and OpenAI - chat, drafting and reasoning tasks
  • Google (Gemini) - image and field-capture extraction
  • Voyage AI - converting your documents into searchable vector embeddings
  • AssemblyAI - converting voice recordings into text

Every provider is accessed over encrypted connections, and each is reviewed against our data-protection standards before we integrate it. We only ever send a model the specific context needed to complete the task at hand - not your entire account's data - which limits exposure by design.

We mirror these protections in our own Agentsy Terms of Service. In short: your data passes through these providers to power the product, and then it stays yours - it isn't used to train anyone's models, and it isn't visible to other customers.

We also keep a human in the loop by design: AI-generated emails, tasks and documents are produced as drafts for your team to review, edit and approve - nothing is sent or actioned externally without a person deciding to.

Document & File Storage

Documents, images, floor plans and voice transcripts you upload or generate in Agentsy are stored securely in Amazon S3, hosted in AWS's Sydney region, so this material stays in Australia. Files are encrypted both at rest and in transit.

Access is strictly segregated: every file is scoped to your organisation at the application layer, and every request for it is checked against that boundary. One customer's data is never visible to another's.

Vector Database

To make your documents searchable and usable by AI, their content is converted into vector embeddings. These are stored in an organisation-scoped vector space within our primary database, so your embeddings are isolated from every other customer's the same way the rest of your data is. A small number of legacy features use Pinecone, a dedicated vector database provider, with the same organisation-level isolation applied via Pinecone's namespace model.

Data Storage & Encryption

Your structured account data - properties, chats, tasks and the like - is held in a managed, encrypted database. Combined with S3 for files, this means every category of your data is encrypted both in transit (TLS/HTTPS on every connection) and at rest.

We go a step further for the most sensitive data we hold: OAuth tokens for connected accounts (like Gmail, Outlook or Calendar) are given an additional layer of application-level encryption on top of database encryption, so that even a database-level exposure would not reveal usable credentials. Passwords are never stored in plain text - they're hashed, never reversible.

Access Control & Authentication

Access within Agentsy is role-based (Owner / Admin / Member), so people on your team only see what they need to. Access to our production systems is limited to a small number of vetted staff. Account sessions use short-lived, automatically-rotating access tokens, and we enforce password strength and automated protection against brute-force login attempts.

Integrations & Authorisation

When you connect a third-party service - email, calendar, or other business tools - we use managed OAuth infrastructure (including Pipedream) to handle the authorisation securely, alongside direct integrations with providers like Microsoft and Google. These connections are entirely opt-in: a service only ever receives your data if you explicitly connect it and grant access, and disconnecting an integration revokes and deletes the associated credentials.

Infrastructure

Agentsy's application and database infrastructure runs on Render, and our frontend is served via Vercel - both established, security-conscious providers. Payments are handled entirely by Stripe, a PCI DSS Level 1 certified provider; we never store your card details ourselves.

Transparency

We believe transparency is itself a security control. We maintain a full, current register of every third-party service that touches customer data - what it's used for, what data it sees, and why - and we're happy to share it as part of any due diligence process.

This is a high-level summary intended to give you confidence in how we handle your data. If you're evaluating Agentsy as part of a formal security or procurement review, get in touch and we'll walk through the detail with you.

Ready to see it
in action?

We'll show you around the platform, run a live debrief for one of your properties, and build a playbook from your own SOPs. Takes 30 minutes.

Post-appraisal debrief
0:42
Vendor follow-up email
Ready to send in under a minute
Drafted
Subject: Tuesday's appraisal - your update
Hi Margaret, thanks again for showing us through. Based on recent comparable sales…
Listing Presentation
Playbook
Template
Take everything from this property folder and my most recent voice notes and develop a complete listing presentation strategy following our agency Playbook.