Skip to content
Legal

Security

How the platform is built, and how to report a problem.

Last updated 9 September 2026

Isolation

Each customer's data lives in its own database rather than in shared tables separated by a filter in application code. A missing `WHERE` clause is the most common way one customer sees another's data, and this removes that class of mistake rather than guarding against it.

The marketing website runs as its own container on its own network segment, with no access to the product database, the vector store or the agent runtime. If it were compromised, the blast radius stops at a brochure.

Payments

Card details are entered on the payment provider's own hosted page and never touch our servers. We do not see, store or transmit card numbers.

The agent tool surface

Every tool this website exposes over WebMCP and the MCP endpoint is read-only except the waitlist submission, which is explicitly annotated as side-effecting so a well-behaved agent asks its user first. Side-effecting tools are not runnable from the on-page console.

The MCP endpoint caps request bodies, does not maintain sessions, and exposes no resources or prompts. Form endpoints are rate-limited per client, size-capped and validated server-side.

Reporting something

Email security@agentbag.ai with what you found and how to reproduce it. We will acknowledge within one business day and keep you informed.

Please do not run automated scanning that degrades the service for other people, and please do not access data belonging to anyone else — report the way in instead, and we will treat you well for it.

Excent RIT Services Ltd · Registered in England and Wales no. 06455789 · VAT GB 926108729
See also refunds & cancellation, about and contact.