Trust Center

Security & compliance at Supercenter

Supercenter is the control plane for enterprise AI agents — skills, integrations and AI coworkers that act inside your existing tools. Security is structural, not bolted on: agents get scoped, encrypted credentials resolved only at execution time; consequential actions require human approval; every tool call is audit-logged with on-behalf-of attribution; and cross-user access exists only through explicit, revocable delegation grants.

This page is generated live from our internal compliance system — the same controls, monitors and vendor register our team operates on. Request access below for the gated document set (DPA, policies, reports).

Documents

Public documents open directly. Locked documents (DPA, policies, reports) are shared with verified companies under confidentiality terms: request access and we will email you a personal, time-limited link, typically within two business days.

report

Security Overview
Architecture, agent-safety model, encryption, audit trails and vulnerability management.
View
GDPR & Data Processing Overview
Processor/controller roles, transfers, AI-specific commitments, DSR and breach handling — for privacy teams.
DORA Readiness (EU financial entities)
How we support customers subject to the EU Digital Operational Resilience Act — contracts, incident assistance, resilience, subprocessors, exit.

certification

Certification Roadmap
GDPR, SOC 2 and ISO 27001 milestones and targets.
View

legal

Privacy Policy
How we collect, use and protect personal data.
View
Terms of Service
The agreement governing use of the platform.
View

policy

Incident Response Plan
Severities, roles, breach-notification flow and exercise cadence.
AI & Agent Governance Policy
Model rules, agent execution controls, delegation and memory governance.
Data Retention & Deletion Schedule
Retention matrix per data class with deletion mechanisms.

Security contact

Vulnerability reports and security questions: security@supercenter.app. Reports are acknowledged within two business days. We do not pursue good-faith research.