Legal

Security Measures

Effective date: 14 May 2026  ·  Last updated: 14 May 2026

This page describes AgentHeaven's baseline technical and organisational measures ("TOMs") for protecting customer data, session logs, credentials, and customer-specific memory/wiki content.

Scope: These measures apply to AgentHeaven-controlled systems, including VPS-hosted agents, custom logs, local file memory/vector stores, and self-hosted model deployments. Third-party providers listed on the Sub-processors page maintain their own security controls.

1. Hosting and Network Security

2. Data Minimisation

3. Customer Isolation

4. Encryption

5. Credentials and Tool Access

6. LLM Routing Controls

7. Logging and Monitoring

8. Personnel and Access

9. Incident Response

10. Deletion and Exit

11. Customer Responsibilities

Security is shared. Customers are responsible for choosing appropriate connected tools, limiting permissions, keeping source data lawful and accurate, reviewing agent outputs, reporting suspicious behaviour promptly, and disabling access in their own systems when no longer needed.

12. Security Contact and Vulnerability Disclosure

Report suspected vulnerabilities, security incidents, or unsafe agent behaviour to info@agentheaven.ai with the subject line "Security". Please include reproduction steps, affected components, and any evidence available. We will acknowledge receipt promptly and coordinate remediation. We do not currently offer a paid bug-bounty programme, but we appreciate responsible disclosure and will credit researchers in our remediation notes on request.