Security

Last updated: April 24, 2026

Protecting your business data and integrations is essential to us. This page describes our approach to security for EzyAgents.

Please report any potential vulnerability by email to security@ezycode.fr. For any other security-related question, contact us at security@ezycode.fr.

Certifications and third-party assessments

EzyAgents is designed to handle sensitive business data. Our platform is GDPR compliant and a Data Processing Agreement (DPA) is available on request to any customer organization.

We commission penetration tests from independent specialized providers, and we fix identified vulnerabilities according to their severity.

A SOC 2 Type II attestation is in progress. Until it is issued, we do not present it as achieved: Enterprise customers can request the current status and our internal controls documentation.

Infrastructure security

All data is encrypted in transit with TLS 1.3 and at rest with AES-256. Integration secrets (API keys, OAuth tokens of your connectors) are protected by an AES-256-GCM application-level encryption envelope, separate from database encryption.

Each customer's data is strictly isolated per tenant. An agent never accesses another organization's data.

Hosting and storage are located in the European Union. Model inference relies on providers contractually committed to neither retaining nor reusing your data to train their models.

Two optional capabilities rely on a US-based provider under the same commitments: choosing OpenAI as model provider (from the Pro plan) and image generation (gpt-image-1, as no image model is available on AWS Bedrock in the European Union). Both are off by default and only turn on by decision of the workspace administrator.

Client and agent security

Human oversight (HITL, Human-In-The-Loop) is at the core of the platform. You define, action by action, what an agent can do autonomously and what requires explicit approval: sending an email, updating the CRM, following up with a customer.

The Tool Guard module enforces guardrails on tools: per-agent access scope, per-domain restrictions and validation of sensitive actions before execution.

Every agent action is timestamped and recorded in an exportable audit log, for full traceability.

Data privacy

Your data belongs to you. We do not sell it, do not share it and never use it to train AI models.

Each customer's knowledge base (documents, procedures, FAQs) is partitioned and only used to answer within their organization.

Internal access is limited to the strict minimum, following the principle of least privilege, and logged.

Securing our own codebase

Every code change is reviewed before deployment. Third-party dependencies are audited, and packages with known unpatched vulnerabilities are rejected.

Production access follows the principle of least privilege and is tracked. Secrets are never committed to the repository.

Account deletion and reversibility

You can export your data at any time from your workspace. Upon an account deletion request, your data is erased from our production systems within the timeframes set by our retention policy.

Enterprise customers can deploy EzyAgents in their own VPC or datacenter, in which case data never leaves their perimeter.

Vulnerability disclosure

We welcome responsible disclosure. Please report any potential vulnerability by email to security@ezycode.fr.

For any other security-related question, contact us at security@ezycode.fr. We commit to acknowledging receipt promptly and keeping you informed as we handle it.

A question about compliance, or a DPA to sign?

Contact the team