AgentFlow helps teams automate document-heavy work while keeping clear limits around information, access, actions, and human approval. Our security program includes data separation, encryption, access controls, monitoring, incident response, backups, and vendor review.
Explore the Security Portal
SOC 2 Type II report available under NDA · Customer data separated by account · Encryption in transit and at rest · Key vendors reviewed
We call this Governed Autonomy. Each workflow has an agreed job, approved information sources, approved actions, and clear review points. Your team stays responsible for final regulated or customer-facing decisions. AgentFlow does not send messages, update core systems, or take other outside actions unless those actions have been approved.
Agree what the workflow can read, use, create, and update.
The workflow follows your policies, thresholds, and exceptions.
People review important or sensitive decisions.
Approved actions. Outside actions stay off until approved. System updates, customer communications, and other actions are enabled only within the agreed workflow.
Why this is different. AgentFlow does more than answer a question. A workflow can read documents, apply business rules, generate output, and connect to other systems. Security, therefore, needs to cover the entire process, not just the prompt and response.
Model training. Unless we agree otherwise in writing, Multimodal does not use customer documents or outputs to train foundation models.
| Action | How it is controlled |
|---|---|
| Read approved documents and fields | Allowed only within the agreed workflow. |
| Create an internal report or result | Allowed within the agreed use case. |
| Send work to a person for review | Set up using the customer's review process. |
| Update a core system | Off unless specifically approved. |
| Send a customer communication | Off unless specifically approved. |
| Make a regulated decision | Remains the customer's responsibility and follows the agreed review process. |
Rules and thresholds can help send the right work to the right person. They support human review; they do not replace customer ownership of important decisions.
AgentFlow keeps records of key workflow activity based on the features in use and the agreed retention period. Available records may show when work was started, changed, reviewed, approved, rejected, completed, or exported.
For supported workflows, records can help connect a result to the source information, business rules, workflow steps, and review actions that produced it.
"Across 100+ playbooks, every execution leaves a reviewable record."
Most customers use AgentFlow as a managed platform with customer accounts kept separate through logical controls. Private-cloud options can be evaluated and scoped separately. Location, support, recovery goals, system connections, and timing are agreed for each deployment.
Protects and operates the AgentFlow platform.
Manages users, connected systems, business rules, and final decisions.
Agree on integrations, review steps, approved actions, retention, and deployment details.
AgentFlow can support work in lending, compliance, privacy, recordkeeping, and model-risk programs. It helps teams carry out their processes, but it does not replace the customer's legal, compliance, or decision-making responsibility.
Bring your security team into the plan. We can walk through the information flow, user access, review steps, approved actions, deployment plan, and available security documents for your use case.
Explore the Security Portal for current controls and evidence, or talk to our team to walk through the information flow, access, review steps, and deployment plan for your use case.