AgentGate Trust Center
AgentGate security architecture, MCP gateway controls, data lifecycle, deployment boundaries and operational commitments.
Security architecture overview
- Agent
Scoped key - Gateway / Local Connector
Inspect → policy → decision - Authorized request
MCP upstream → tool - Control plane
Approvals + PostgreSQL audit
The gateway evaluates routed calls before forwarding. Local Connector obtains authorization before invoking a local upstream. Network and credential boundaries must force tools through the gateway; a direct bypass cannot be controlled by an intermediary.
Data handling and redaction
Audit records include tenant and agent identity, tool/server, timestamps, decision, risk and redacted argument context. Account services process sign-in and subscription information. Secret detection is pattern-based; unrecognized sensitive data can remain, so minimize arguments and review exports.
Audit retention
Worker-enforced plan retention
| Plan | Audit window | Reason |
|---|---|---|
| Trial | 7 days | Weekly technical review with a small evaluation footprint. |
| Team | 90 days | A quarter of evidence for change and incident review. |
| Enterprise | 365 days | Annual review and rollout comparison. |
For a self-hosted deployment, the operator owns archival, deletion and backup lifecycle. The specific diagnostics and backup retention windows are configured per deployment and are not fixed by the codebase; restoring a backup requires reapplying the current retention boundary. The worker checks expired records every minute in batches of 5,000. Unresolved executions are held for investigation. Backup copies have a separate operator-managed lifecycle.
Tenant isolation
Management requests use tenant claims and RBAC checks. Agent credentials identify the tenant at the gateway; data access is tenant-scoped. Private deployments put infrastructure under the customer's control. Physical isolation and an independent penetration-test certification are not claimed.
Availability and fail-closed behavior
No matching policy means deny. A missing connector authorization response grants no permission. Before remote execution, the gateway persists an immutable authorization record. If persistence fails, execution stops. Outcomes are appended separately. An interrupted outcome is reported as uncertain and creates an in-product alert; inspect upstream evidence before retrying. No standard uptime percentage or recovery-time guarantee is advertised; this codebase ships no uptime measurement system, and availability commitments, if any, are defined in the deployment agreement rather than in the product.
Self-hosting deployment model
Docker Compose and Helm deployment code are provided. The following complete local evaluation stack uses a separate network, database and mail capture, with loopback-only ports. It sends no real email and uses a controlled MCP fixture.
docker compose -f tests/evaluation-compose.yml up -d --build
node scripts/evaluation-e2e.mjs
# Dashboard: http://127.0.0.1:18080
# API: http://127.0.0.1:18090
# Gateway: http://127.0.0.1:18091For Kubernetes, deploy/helm contains the chart and values. Build your images, supply private image tags and secret-backed database/Redis settings, run helm template, then install into your customer-owned cluster. AgentGate does not operate a fixed cloud provider or geographic region; the operator's infrastructure choice determines hosting region. Deployment-specific secrets belong in your secret store, never in documentation examples.
Backup and recovery
Use scripts/backup-postgres.ps1 to stream a PostgreSQL custom-format backup and generate a SHA-256 checksum. Supply the Compose file, database, database user and a protected output directory. scripts/evaluation-recovery.mjs rehearses restoration into a new isolated database and checks that evidence and immutability survive. Store backups encrypted with access controls and a deployment-specific expiry schedule. The worker deletes expired live audit records; retained backups must follow your separate recovery and deletion policy.
Subprocessors
Derived from codebase and deployment configuration · not a legal subprocessor register
| Infrastructure / processor | Purpose |
|---|---|
| PostgreSQL | Primary data store for tenant, policy and audit records. |
| Redis | Caching and ephemeral coordination state. |
| Mailgun | Transactional email delivery (account, billing and security notices). |
| Paddle | Payment processing, tax calculation and subscription billing (Merchant of Record). |
| Cloudflare | DNS and TLS origin certificate handling. |
Paddle is the sole payment processor wired into checkout for this product; any other billing code present in the repository at a given time is not part of the active checkout path and should not be treated as a live subprocessor. This list reflects infrastructure and third-party integrations wired into this codebase and its deployment configuration; it is not a legally reviewed subprocessor register, does not capture which processors are active for a specific customer deployment, and is not a substitute for a signed DPA. Request the deployment-specific processing inventory and current subprocessor list through the enterprise evaluation contact before sending personal data. Source integrations alone are not a legal subprocessor register, and no NDA inventory is claimed to exist here.
Privacy and DPA
Privacy notice · Data processing addendum · Pricing and retention model.
Security contact and responsible disclosure
Use [email protected] for an initial report containing affected version, minimal reproduction, expected behavior and impact. Do not attach keys or customer records. Request a private transfer channel for sensitive evidence and coordinate disclosure after remediation. No response-time SLA or encryption-key service is advertised.
Compliance status
Compliance documentation available during enterprise evaluation. Security documentation and architecture review are available on request.
We have a SOC 2 plan. No SOC 2 or ISO certification or customer endorsement is claimed until an audit is complete. External WORM storage and SSO are outside the offered implementation.
