THREESIXTY.

Trust center

Trust, compliance & operations security

Procurement-friendly summary of how we protect your data, limit blast radius, and give security teams evidence they can validate, while keeping agents operational around the clock.

Global compliance

Personal and sensitive data processing stays within the boundaries you define. GDPR-aligned practices apply to enquiries and contracted delivery; UK and EU transfers use appropriate safeguards (e.g. UK IDTA / EU SCCs) where applicable.

We describe our posture as SOC 2 ready, controls and evidence mapped to common questionnaire themes so your security team can validate quickly during vendor review.

Secrets & credentials

Provider API keys and operational secrets are stored in a dedicated secrets manager, not scattered in config files. Your security team gets rotation visibility so they know when credentials were last updated.

Technical controls: secrets

Provider API keys and operational secrets are managed through Infisical on our ops stack. Command Center tracks centrally managed provider credentials with rotation visibility.

Network isolation

Customer agent machines join a private mesh with hub-and-spoke access: ops can reach agents for continuity work; agents cannot reach each other. That limits lateral movement if a single runtime is compromised.

Technical controls: networking

Customer Claw machines join a Tailscale mesh with hub-and-spoke ACLs: Command Center and ops infrastructure can reach agents on port 8000; Claws cannot reach each other.

Remote operations & session audit

When restoring an agent to last known good state, human operators use secure, browser-based remote access with session audit where agreed. Least privilege, scoped systems only, and actions tied to the platform audit log.

Technical controls: remote access

We use MeshCentral and Guacamole for browser-based access with session audit where agreed, no lateral movement outside scoped systems.

Safety & audit evidence

Safety policies are enforced at the agent and gateway layers, with violations reported into Command Center for review. Operator and system actions are recorded in an immutable audit log suitable for SOC 2 and internal review. See our safety & governance overview for portal reporting and governance features.

Technical controls: ClawGuard

ClawGuard enforces policies at the agent and gateway layers, tool validation, request inspection, and violation reporting into Command Center.

Data residency & sovereignty

Your data does not need to leave your chosen sovereign territory for routine continuity work: workloads remain in your cloud or hosting boundary where you require it. We coordinate access, change windows, and logging so residency commitments stay intact.

Security contact

For vulnerability reports and security questionnaires, reach out through your commercial contact or start an AI Health Audit request so we can route you to the right owner.