Skip to content
Last updated

Security and compliance

Agen for SaaS is designed with security and compliance at every layer. Every AI agent interaction passes through a multi-layered governance pipeline that enforces authentication, authorization, policy evaluation, data protection, and full audit logging.


Security architecture

The Agen for SaaS MCP Gateway enforces the following security layers on every request:

LayerPurpose
AuthenticationEvery request must include a valid identity token. Supports Frontegg and any OIDC-compliant provider.
Access controlJWT-based role and permission checks ensure only authorized users can invoke specific tools.
PoliciesConditional rules evaluate request context and enforce deny, step-up, or approval actions.
Approval flowsHuman-in-the-loop review for sensitive operations with multi-step, multi-channel notifications.
Data protectionAutomatic masking of PII, PHI, PCI, and other sensitive data types in tool responses.
HooksCustom JavaScript code for additional validation, transformation, and enforcement logic.
MonitoringFull audit trail of every interaction, policy decision, and approval event.

Compliance coverage

Agen for SaaS helps you meet requirements for:

FrameworkHow Agen for SaaS helps
SOC 2Full audit logging of all AI agent actions, policy enforcement, and approval workflows.
GDPRData protection policies with GDPR-specific masking types. Conditional targeting for EU data subjects.
HIPAAPHI masking with 39 predefined health data types. Access control and approval flows for health data tools.
PCI DSSPayment card data masking. Tool-level access restrictions for payment endpoints.
CCPACalifornia-specific data type masking and conditional enforcement.