SaaSFactory.ai Security Policy
This page describes how SaaS Factory protects the platform and your data, and what security is your responsibility. It restates commitments in the Terms of Service and DPA; those govern if anything differs.
1. Encryption. All traffic is encrypted in transit using TLS 1.2 or higher with a publicly trusted certificate, renewed automatically. Data is encrypted at rest by our infrastructure providers. We do not commit to a specific certificate authority or validation level (terms, clause 53.5).
2. Infrastructure. Products run on enterprise grade providers (listed under Terms & Legals, Sub-processors), each holding recognised certifications such as SOC 2 and ISO 27001. Environments are segregated, access is controlled and logged, and backups run automatically. Enterprise adds multi region database backup.
3. Access to your data. We do not access your product’s end user data in the ordinary course of business. Access happens only for troubleshooting, security, safety, abuse prevention or legal compliance, under the controls in the DPA (terms, clause 48.4).
4. Authentication. Email and password, SSO and two factor authentication are available. We recommend SSO with 2FA. Anything done through a valid session is deemed authorised by you until you report compromise (terms, clause 55).
5. Monitoring and error capture. We monitor the platform for abuse, fraud and instability, and capture runtime errors through signed project tokens. Keep your tokens secure; a leaked token can pollute your error data (terms, clauses 49 and 54).
6. AI specific security. AI connected features, including the MCP server, face evolving attack classes such as prompt injection that no provider can fully prevent. We apply reasonable technical measures and give no warranty against such attacks. You scope what AI workers and MCP connections can reach (terms, clauses 22 and 50).
7. Your responsibilities. Safeguard credentials, remove leavers promptly, scope AI worker permissions, keep DNS and email authentication records correct, test releases, and report suspected compromise immediately to support@saasfactory.ai.
8. Reporting a vulnerability. If you find a security vulnerability, report it to support@saasfactory.ai with enough detail to reproduce it. Do not access other customers’ data, disrupt the service, or publicly disclose before we have had reasonable time to fix. We acknowledge reports and act on verified issues; we do not currently run a paid bounty programme.
9. Breach notification. If a personal data breach affects your end user data, we notify you without undue delay with the information we have (DPA, section 8). Notifying authorities and your end users is your duty as controller.
10. Enterprise. A vendor security review pack for procurement teams is available on the Enterprise tier.
agentOS Proptech Group Ltd t/a SaaSFactory.ai · 13 Lambourne Crescent, Llanishen, Cardiff, Wales, CF14 5GF · support@saasfactory.ai