Security Designed for Work That Reads, Decides, and Acts

AgentFlow helps teams automate document-heavy work while keeping clear limits around information, access, actions, and human approval. Our security program includes data separation, encryption, access controls, monitoring, incident response, backups, and vendor review.

Explore the Security Portal

Talk to our team

SOC 2 Type II report available under NDA · Customer data separated by account · Encryption in transit and at rest · Key vendors reviewed

Automation That Stays Within the Limits You Approve

We call this Governed Autonomy. Each workflow has an agreed job, approved information sources, approved actions, and clear review points. Your team stays responsible for final regulated or customer-facing decisions. AgentFlow does not send messages, update core systems, or take other outside actions unless those actions have been approved.

Clear scope

Agree what the workflow can read, use, create, and update.

Your rules

The workflow follows your policies, thresholds, and exceptions.

Human approval

People review important or sensitive decisions.

Approved actions. Outside actions stay off until approved. System updates, customer communications, and other actions are enabled only within the agreed workflow.

Why this is different. AgentFlow does more than answer a question. A workflow can read documents, apply business rules, generate output, and connect to other systems. Security, therefore, needs to cover the entire process, not just the prompt and response.

A Clear Path From Source Document to Reviewed Result

  1. Approved information — Use only the documents, fields, systems, and connections needed for the agreed workflow.
  2. Protected processing — Encrypt customer information and keep customer accounts logically separate.
  3. Rules and checks — Apply the agreed business rules, checks, and workflow steps.
  4. Human review — Send important work to the right person based on the customer's review rules.
  5. Approved delivery — Download results or send them through approved connections.
  6. Agreed data rules — Follow the agreement for retention, deletion, exports, and backups.

Model training. Unless we agree otherwise in writing, Multimodal does not use customer documents or outputs to train foundation models.

Who Controls Each Action

ActionHow it is controlled
Read approved documents and fieldsAllowed only within the agreed workflow.
Create an internal report or resultAllowed within the agreed use case.
Send work to a person for reviewSet up using the customer's review process.
Update a core systemOff unless specifically approved.
Send a customer communicationOff unless specifically approved.
Make a regulated decisionRemains the customer's responsibility and follows the agreed review process.

Rules and thresholds can help send the right work to the right person. They support human review; they do not replace customer ownership of important decisions.

A Record Your Team Can Review

AgentFlow keeps records of key workflow activity based on the features in use and the agreed retention period. Available records may show when work was started, changed, reviewed, approved, rejected, completed, or exported.

For supported workflows, records can help connect a result to the source information, business rules, workflow steps, and review actions that produced it.

"Across 100+ playbooks, every execution leaves a reviewable record."

A Deployment Plan Built With Your Team

Most customers use AgentFlow as a managed platform with customer accounts kept separate through logical controls. Private-cloud options can be evaluated and scoped separately. Location, support, recovery goals, system connections, and timing are agreed for each deployment.

Multimodal

Protects and operates the AgentFlow platform.

Customer

Manages users, connected systems, business rules, and final decisions.

Together

Agree on integrations, review steps, approved actions, retention, and deployment details.

AgentFlow can support work in lending, compliance, privacy, recordkeeping, and model-risk programs. It helps teams carry out their processes, but it does not replace the customer's legal, compliance, or decision-making responsibility.

The Proof Your Teams Need

  • Security Portal — Security controls and current evidence.
  • SOC 2 Type II report — Available through the secure request process.
  • Data Processing Addendum — How personal data is handled.
  • Security Addendum — The security measures that apply.
  • AI Governance Addendum — Who controls AI-assisted work and decisions.
  • Vendor and provider list — The companies involved in delivering the service.
  • Security issue reporting — How to report a security concern.
  • Insurance evidence — Available through the secure request process.

Bring your security team into the plan. We can walk through the information flow, user access, review steps, approved actions, deployment plan, and available security documents for your use case.

Bring Your Security Team Into the Plan

Explore the Security Portal for current controls and evidence, or talk to our team to walk through the information flow, access, review steps, and deployment plan for your use case.