Security architecture
Isolation, permissions, brokered secrets, controlled egress, audit evidence, and deployment boundaries.
Start with the public record. When the answer depends on your deployment, bring us into the review and test the exact boundary.
Last reviewed · August 2026
These resources are public and do not require an account, NDA, or sales conversation.
Isolation, permissions, brokered secrets, controlled egress, audit evidence, and deployment boundaries.
What Delegate stores, where agent work is processed, artifact retention, and deletion boundaries.
The product-level model for permissions, approvals, credentials, and accountable agent work.
The information Delegate collects, how it is used and shared, and the rights available to individuals.
The terms governing accounts, customer content, AI-generated output, and use of the service.
Provider terms, infrastructure services, data residency, and operating responsibility change with the deployment. We will not answer those questions with a generic badge.
Walk through the managed-cloud, customer-cloud, or on-premises boundary with your infrastructure and security teams.
Request architecture reviewConfirm the model providers, infrastructure services, retention, backup, residency, and contractual terms in scope for your deployment.
Request data reviewBring your organization’s questionnaire and evidence requirements. We will answer against the deployment you are evaluating.
Start a questionnaireSend a suspected vulnerability or security issue directly to the Delegate team for triage.
Report a concernDelegate does not currently claim SOC 2 or ISO 27001 certification. Completed independent assurance and testing evidence will be published here when it exists; framework references elsewhere describe design alignment only.
Review the security model