AgentGate Labs
Menu

AgentGate Trust Center

AgentGate security architecture, MCP gateway controls, data lifecycle, deployment boundaries and operational commitments.

Security architecture overview

  1. Agent
    Scoped key
  2. Gateway / Local Connector
    Inspect → policy → decision
  3. Authorized request
    MCP upstream → tool
  4. Control plane
    Approvals + PostgreSQL audit

The gateway evaluates routed calls before forwarding. Local Connector obtains authorization before invoking a local upstream. Network and credential boundaries must force tools through the gateway; a direct bypass cannot be controlled by an intermediary.

Data handling and redaction

Audit records include tenant and agent identity, tool/server, timestamps, decision, risk and redacted argument context. Account services process sign-in and subscription information. Secret detection is pattern-based; unrecognized sensitive data can remain, so minimize arguments and review exports.

Audit retention

Worker-enforced plan retention

PlanAudit windowReason
Trial7 daysWeekly technical review with a small evaluation footprint.
Team90 daysA quarter of evidence for change and incident review.
Enterprise365 daysAnnual review and rollout comparison.

For a self-hosted deployment, the operator owns archival, deletion and backup lifecycle. The specific diagnostics and backup retention windows are configured per deployment and are not fixed by the codebase; restoring a backup requires reapplying the current retention boundary. The worker checks expired records every minute in batches of 5,000. Unresolved executions are held for investigation. Backup copies have a separate operator-managed lifecycle.

Tenant isolation

Management requests use tenant claims and RBAC checks. Agent credentials identify the tenant at the gateway; data access is tenant-scoped. Private deployments put infrastructure under the customer's control. Physical isolation and an independent penetration-test certification are not claimed.

Availability and fail-closed behavior

No matching policy means deny. A missing connector authorization response grants no permission. Before remote execution, the gateway persists an immutable authorization record. If persistence fails, execution stops. Outcomes are appended separately. An interrupted outcome is reported as uncertain and creates an in-product alert; inspect upstream evidence before retrying. No standard uptime percentage or recovery-time guarantee is advertised; this codebase ships no uptime measurement system, and availability commitments, if any, are defined in the deployment agreement rather than in the product.

Self-hosting deployment model

Docker Compose and Helm deployment code are provided. The following complete local evaluation stack uses a separate network, database and mail capture, with loopback-only ports. It sends no real email and uses a controlled MCP fixture.

docker compose -f tests/evaluation-compose.yml up -d --build
node scripts/evaluation-e2e.mjs
# Dashboard: http://127.0.0.1:18080
# API: http://127.0.0.1:18090
# Gateway: http://127.0.0.1:18091

For Kubernetes, deploy/helm contains the chart and values. Build your images, supply private image tags and secret-backed database/Redis settings, run helm template, then install into your customer-owned cluster. AgentGate does not operate a fixed cloud provider or geographic region; the operator's infrastructure choice determines hosting region. Deployment-specific secrets belong in your secret store, never in documentation examples.

Backup and recovery

Use scripts/backup-postgres.ps1 to stream a PostgreSQL custom-format backup and generate a SHA-256 checksum. Supply the Compose file, database, database user and a protected output directory. scripts/evaluation-recovery.mjs rehearses restoration into a new isolated database and checks that evidence and immutability survive. Store backups encrypted with access controls and a deployment-specific expiry schedule. The worker deletes expired live audit records; retained backups must follow your separate recovery and deletion policy.

Subprocessors

Derived from codebase and deployment configuration · not a legal subprocessor register

Infrastructure / processorPurpose
PostgreSQLPrimary data store for tenant, policy and audit records.
RedisCaching and ephemeral coordination state.
MailgunTransactional email delivery (account, billing and security notices).
PaddlePayment processing, tax calculation and subscription billing (Merchant of Record).
CloudflareDNS and TLS origin certificate handling.

Paddle is the sole payment processor wired into checkout for this product; any other billing code present in the repository at a given time is not part of the active checkout path and should not be treated as a live subprocessor. This list reflects infrastructure and third-party integrations wired into this codebase and its deployment configuration; it is not a legally reviewed subprocessor register, does not capture which processors are active for a specific customer deployment, and is not a substitute for a signed DPA. Request the deployment-specific processing inventory and current subprocessor list through the enterprise evaluation contact before sending personal data. Source integrations alone are not a legal subprocessor register, and no NDA inventory is claimed to exist here.

Privacy and DPA

Privacy notice · Data processing addendum · Pricing and retention model.

Security contact and responsible disclosure

Use [email protected] for an initial report containing affected version, minimal reproduction, expected behavior and impact. Do not attach keys or customer records. Request a private transfer channel for sensitive evidence and coordinate disclosure after remediation. No response-time SLA or encryption-key service is advertised.

Compliance status

Compliance documentation available during enterprise evaluation. Security documentation and architecture review are available on request.

We have a SOC 2 plan. No SOC 2 or ISO certification or customer endorsement is claimed until an audit is complete. External WORM storage and SSO are outside the offered implementation.