Security

Where things run, what we can and cannot see, and how to reach us. Written plainly. Where we do not have an answer yet, we say so.

Where it runs, where your data lives

A deployment can run in a cloud account you control or in infrastructure operated by Square Agent. That choice changes who can access the infrastructure, where secrets and logs live, and who handles incidents. It does not automatically change a model provider’s handling of data sent to its API.

What Square Agent can and cannot see

Self-hosted

Your Azure subscription, Google Cloud project, or Cloudflare account

  • You control the cloud account and the deployment secret store.
  • The agreed architecture defines which prompts, tool results and logs stay in that account.
  • Square Agent support access, if any, must be granted by you and recorded in the contract.
  • Your model provider may still receive prompts and tool results. Its retention terms remain a separate boundary.

Managed by Square Agent

We host and operate the gateway for you

  • Prompts, tool results and logs may pass through infrastructure we operate.
  • Tool credentials are stored in the deployment secret store, separate from the AI client.
  • Retention, log export, data location and Square Agent support access are agreed for the deployment.
  • We will not claim a control or certification that the deployed service has not been verified against.

Identity and access

Employee deployments connect a company identity provider and map staff to approved actions. The exact provider, group source and policy checks depend on the agreed integration.

Customer-facing Live deployments use customer authentication, consent and access limited to that customer’s account or resources. They do not reuse employee permissions. Rate limits, recovery flows and account separation must be designed and tested for that service.

Credentials

When the Gateway handles a tool call, its credentials live in the deployment’s secret store. The gateway retrieves the credential after it allows the call and sends it to the approved tool, not to the AI client. Direct MCP connections have their own credential boundary and need a separate review.

Audit

A Gateway deployment can record the caller, client, tool, action and policy decision. The deployment contract must state the log location, retention period, export method and who may read it. These details are not universal across every deployment today.

Reporting a vulnerability

If you believe you have found a security issue in anything we run, email security@squareagent.co.uk. We will confirm receipt and explain the next step. Response times and disclosure terms depend on the support agreement in place.

What this page does not cover

Ask us for the current position on certifications, penetration testing, subprocessors, data processing terms, retention and incident response. If a control is planned but not verified for your deployment, we will mark it as such.

Talk through the work

Bring a technical problem or an opportunity you think AI could help with. We will use 20 minutes to work out whether there is a useful next step.

Book a conversation