Security & data
Agents you can trust with real work.
An agent works inside your business systems, so how it gets access, who approves its actions and what happens to your data matter as much as what it does. Here is how we handle each.
How agents operate
Clear permissions, human approval and a full record.
Access you approve, and can revoke
Agents connect through the APIs, webhooks and approved automation paths your platforms provide, with only the permissions the role needs. You decide what each agent can see and do, and you can disconnect an integration at any time.
Humans stay in charge
Sensitive actions such as refunds above a limit or spend above a threshold wait for a person to approve them. Escalation rules route anything unusual to a named owner on your team.
Every action is logged
Each deployment keeps an activity history of what the agent did and when, plus live status, approvals and exceptions surfaced for human review. Nothing happens in a black box.
Exceptions, not silence
When an agent isn't sure, or something falls outside its rules, it stops and flags it rather than guessing. Exceptions are visible to your team and reviewed as part of how we manage each agent.
Your data
Used for your service, governed by your contract.
Your data is used for your service only
Client data is used to provide the contracted service, follow your documented instructions, keep it secure and meet legal obligations. It is not used for advertising, unrelated model training or unrelated product development.
Contracts set the rules
For client projects, your project agreement and data processing agreement (DPA) govern how personal data is processed. We act on your documented instructions and help you respond to requests from your own users.
Where data is stored
Data is stored with the providers and in the locations selected for your service, and these are identified in your service notice or contract. Before any transfer or remote access from outside India, we agree the safeguards the law requires.
Return and deletion
Your instructions and contract decide how project data is returned, exported, deleted or retained. Copies in protected backups are removed through normal overwrite and are never used for anything else.
If something goes wrong
We use technical and organisational safeguards proportionate to the data and the service, such as access controls, confidentiality commitments, secure configuration, logging and incident handling. The specific controls for your service are set out in its security schedule or DPA. If an incident affects data we process for you, we notify you under your contract and applicable law so you can assess your own obligations.
What we won't claim
We don't advertise certifications, hosting regions or encryption standards unless they've been verified for the service in question. If your organisation needs specific assurances, we'll set them out in writing in your contract, where they belong.
This website
How keystonetech.si handles your details.
A private activity log
Briefs, suggestions and calendar openings are recorded with the time and your IP address. The log is kept outside the public website and only Keystone's administrators can view it. We use it to keep our records accurate and to spot misuse.
Where this website runs
This website and its form submissions are hosted on servers in Singapore, served over HTTPS. Analytics cookies are only used if you accept them; see our Cookie Policy.
Please don't send sensitive data
Don't include passwords, financial account credentials or health information in a form, email or chat. If you're an existing client, use your designated project channel.
Read more in our Privacy Policy, Cookie Policy and Terms & Conditions. Security questions or concerns: info@keystonetech.si.
Questions about access or data? Ask us before you sign anything.
We'll walk you through exactly what an agent would connect to, what it could do, and how you'd stay in control.

