Security Designed for Work That Reads, Decides, and Acts

AgentFlow helps teams automate document-heavy work while keeping clear limits around information, access, actions, and human approval. Our security program includes data separation, encryption, access controls, monitoring, incident response, backups, and vendor review.

SOC 2 Type II report available under NDA · Customer data separated by account · Encryption in transit and at rest · Key vendors reviewed

SeparationCustomer data separated by account
EncryptionIn transit and at rest
MonitoringAccess controls, monitoring & incident response
AssuranceBackups, vendor review & SOC 2 Type II
Governed Autonomy

Automation That Stays Within the Limits You Approve

We call this Governed Autonomy. Each workflow has an agreed job, approved information sources, approved actions, and clear review points. Your team stays responsible for final regulated or customer-facing decisions. AgentFlow does not send messages, update core systems, or take other outside actions unless those actions have been approved.

Clear scope

Agree what the workflow can read, use, create, and update.

Your rules

The workflow follows your policies, thresholds, and exceptions.

Human approval

People review important or sensitive decisions.

Approved actions. Outside actions stay off until approved. System updates, customer communications, and other actions are enabled only within the agreed workflow.

Why this is different. AgentFlow does more than answer a question. A workflow can read documents, apply business rules, generate output, and connect to other systems. Security, therefore, needs to cover the entire process, not just the prompt and response.

Information Flow

A Clear Path From Source Document to Reviewed Result

1

Approved information

Use only the documents, fields, systems, and connections needed for the agreed workflow.

2

Protected processing

Encrypt customer information and keep customer accounts logically separate.

3

Rules and checks

Apply the agreed business rules, checks, and workflow steps.

4

Human review

Send important work to the right person based on the customer's review rules.

5

Approved delivery

Download results or send them through approved connections.

6

Agreed data rules

Follow the agreement for retention, deletion, exports, and backups.

Model training. Unless we agree otherwise in writing, Multimodal does not use customer documents or outputs to train foundation models.

Access Control

Who Controls Each Action

Rules and thresholds can help send the right work to the right person. They support human review; they do not replace customer ownership of important decisions.

ActionHow it is controlled
Read approved documents and fieldsAllowed only within the agreed workflow.
Create an internal report or resultAllowed within the agreed use case.
Send work to a person for reviewSet up using the customer's review process.
Update a core systemOff unless specifically approved.
Send a customer communicationOff unless specifically approved.
Make a regulated decisionRemains the customer's responsibility and follows the agreed review process.
Auditability

A Record Your Team Can Review

AgentFlow keeps records of key workflow activity based on the features in use and the agreed retention period. Available records may show when work was started, changed, reviewed, approved, rejected, completed, or exported.

For supported workflows, records can help connect a result to the source information, business rules, workflow steps, and review actions that produced it.

Across 100+ playbooks, every execution leaves a reviewable record.

// AgentFlow activity log
Deployment

A Deployment Plan Built With Your Team

Most customers use AgentFlow as a managed platform with customer accounts kept separate through logical controls. Private-cloud options can be evaluated and scoped separately. Location, support, recovery goals, system connections, and timing are agreed for each deployment.

Multimodal

Protects and operates the AgentFlow platform.

Customer

Manages users, connected systems, business rules, and final decisions.

Together

Agree on integrations, review steps, approved actions, retention, and deployment details.

AgentFlow can support work in lending, compliance, privacy, recordkeeping, and model-risk programs. It helps teams carry out their processes, but it does not replace the customer's legal, compliance, or decision-making responsibility.

Evidence

The Proof Your Teams Need

Security Portal

Security controls and current evidence.

SOC 2 Type II report

Available through the secure request process.

Data Processing Addendum

How personal data is handled.

Security Addendum

The security measures that apply.

AI Governance Addendum

Who controls AI-assisted work and decisions.

Vendor and provider list

The companies involved in delivering the service.

Security issue reporting

How to report a security concern.

Insurance evidence

Available through the secure request process.

Bring your security team into the plan. We can walk through the information flow, user access, review steps, approved actions, deployment plan, and available security documents for your use case.

Bring Your Security Team Into the Plan

Explore the Security Portal for current controls and evidence, or talk to our team to walk through the information flow, access, review steps, and deployment plan for your use case.