---
title: "AI Agent Security and Procurement Facts | FidelicAI"
description: "See how FidelicAI scopes customer access, handles credentials and data, records work, and states its current SOC 2, DPA, insurance, and uptime evidence."
canonical: "https://fidelic.ai/security"
dateModified: "2026-08-23"
---

# Keep the work visible and the access narrow

Each fidelic agent works from customer-approved sources, carries checks and approvals with the result, and writes the work where the accountable team can inspect it. The procurement record marks current evidence and every gap.

## Data path

A fidelic agent reads only customer sources approved for the job, uses model, hosting, connection, and payment providers where the service requires them, and writes the result into the agreed work environment or customer system. The exact providers and permissions vary by agent.

1. **Approved source:** a customer account, file, message, record, or public source named for the work.
2. **Scoped processing:** the service and its providers process what the approved work requires.
3. **Checked result:** sources, acceptance checks, open questions, and approval state travel with the output.
4. **Customer record:** work is written into Slack, WhatsApp, Teams, or the connected system agreed for the job.

## Six controls built into the customer path

- Verified customer identity at customer-data boundaries.
- Customer-scoped connections that the customer can revoke.
- Slack tokens, Google credentials, partner codes, and provider secrets stay out of browser code and customer-visible logs.
- External, binding, irreversible, licensed, employment, spending, and public-record actions wait for the named owner or qualified professional.
- The result, sources, open questions, and approval state remain visible in the agreed system.
- Customer-facing errors omit provider bodies, credentials, authorization codes, and stack traces.

## Procurement facts mark every published and missing document

- **Customer agreement: published:** the [agreement shown before payment](https://start.fidelic.ai/terms) covers ownership, connected services, billing, cancellation, liability, and the delivery remedy.
- **Security contact: available:** send questions to [hello@fidelic.ai](mailto:hello@fidelic.ai?subject=Security%20and%20procurement%20review).
- **FidelicAI SOC 2 report: not claimed:** a provider report is not a FidelicAI report.
- **Data processing addendum: not published:** a standard DPA is not published today.
- **Subprocessor register: not published:** provider categories are disclosed, but a vendor-by-vendor register and change-notice process are not yet public.
- **Insurance certificate: not published:** FidelicAI does not publish a technology E&O, professional-liability, or cyber-insurance certificate today.
- **Status and uptime history: not published:** there is no public status page or historical uptime record today.

## Work environments

- **Slack:** the shared-team view for work, corrections, questions, and approvals.
- **WhatsApp:** a compact owner briefing and decision surface; full work products stay in connected systems.
- **Microsoft Teams:** the governed Microsoft 365 surface; account ownership, channel, and retention are stated before work begins.

## Use the public agreement for ordinary business records

Do not send health records, payment card numbers, government identification numbers, or material covered by a confidentiality obligation you cannot extend to a vendor. The public service does not currently publish a FidelicAI SOC 2 report, standard DPA, subprocessor register, BAA, insurance certificate, or historical uptime record.

Legal, finance, insurance, employment, compliance, and intellectual-property agents may prepare and maintain the factual record. The licensed decision, professional opinion, filing authority, and final sign-off remain with the relevant person.

## Public work proves owner visibility

[New Street Studios](https://fidelic.ai/new-street-studios) shows fidelic agents posting work, naming blocked handoffs, and waiting for approval in Slack. It demonstrates an owner-visible work record. It does not verify isolation, data handling, insurance, or compliance.

Review the [delivery promise](https://fidelic.ai/guarantee), [privacy policy](https://fidelic.ai/privacy), and [role-specific limits](https://fidelic.ai/agents).

## Citation

FidelicAI. "AI agent security and procurement facts." Updated August 23, 2026. https://fidelic.ai/security
