Skip to content
Last updated

Compliance

Agen for SaaS provides built-in capabilities to help your organization meet regulatory compliance requirements when exposing product capabilities to AI agents.


Compliance capabilities by regulation

SOC 2

RequirementHow Agen for SaaS helps
Access controlRole-based and permission-based tool restrictions using JWT attributes.
Audit loggingFull audit trail of every tool call, policy decision, and approval event.
Change managementPolicy and configuration changes are tracked with timestamps.
Incident responseReal-time monitoring and log streaming to SIEM platforms.

GDPR

RequirementHow Agen for SaaS helps
Data minimizationData protection policies mask GDPR-regulated data types in tool responses.
Lawful processingAccess control and policies ensure data is only accessed by authorized users for authorized purposes.
Data subject rightsConditional targeting applies masking based on user geography (e.g., EU data subjects).
AccountabilityComplete audit trail demonstrates compliance with data protection principles.

HIPAA

RequirementHow Agen for SaaS helps
Access controlsRole-based restrictions on health data tools.
Audit controlsComprehensive logging of all PHI access through AI agents.
Transmission securityTLS encryption for all MCP Gateway communications.
Data protection39 predefined PHI masking types covering international health identifiers.

PCI DSS

RequirementHow Agen for SaaS helps
Restrict accessAccess control rules limit which users can invoke payment-related tools.
Protect cardholder dataPCI data masking in tool responses prevents exposure of card numbers and CVVs.
Monitor accessFull logging of all payment tool interactions.

CCPA / COPPA

RequirementHow Agen for SaaS helps
Data protectionDedicated masking categories for CCPA and COPPA data types.
Conditional enforcementPolicy targeting allows geography-specific and age-specific compliance rules.