Secure AI Agent · Cloud and Hosting

AI applied to what is yours and what is the client's

A specialist configured to document the shared responsibility boundary, answer abuse against the clock, and prove the backup restore works — not just that the job ran.

Companies that trust UPX

  • Bradesco
  • Nubank
  • BTG Pactual
  • Totvs
  • Ascenty
  • Live!
  • G4 Educação
  • EVEO

Capabilities

What the Cloud and Hosting Agent can do

Main areas of work for the Cloud and Hosting Provider AI Agent in your operation.

Shared responsibility

Documents what belongs to the provider and to the client.

Abuse against the clock

Triages the report, identifies the account, and drafts the reply.

Tested restores

Tracks the recovery test, not just the backup job.

Environment posture

Flags open ports, broad permissions, and exposed resources.

Technical tickets

Classifies the case and separates what is on the client's side.

Patch windows

Organizes patching, client notice, and the rollback plan.

Skills

Capabilities that compose the specialist

Skills add specific capabilities to the Secure AI Agent according to the processes it needs to execute.

Restore verification
Confirms the recovery was tested and actually worked.
Abuse triage
Correlates the indicator with the responsible account.
Responsibility matrix
Documents the contracted boundary per service.
How it works

From the report and the backup to a defensible operation

Connect your sources, define what the agent can do, and run multi-tenant operations with a clear boundary.

01

Connect the cloud and the tickets
Each client in an isolated scope.Connect the cloud providers, the monitoring, the account base, and the tickets so the Secure AI Agent has access only to what it needs — without reaching the client's hosted content.

02

Ask for the work
Talk to the agent in natural language.Ask for abuse triage, the status of restore tests, or an environment's posture through the available channels. The agent understands the context, applies the configured skills, and cites the evidence.

03

The agent verifies. You decide.
From verification to action, with control.The agent triages, documents, and tests within the defined permissions. Suspending accounts, taking down instances, and accessing hosted data still require human approval.

Integrations

Connected to the clouds you operate

The Cloud and Hosting Agent can query your environment and run tasks in the systems your team already uses.

  • AWS
  • Microsoft Azure
  • Google Cloud
  • Cloudflare
  • Grafana

Flow

What goes in, what the agent does, and what comes out

From a job that ran to a proven recovery, following the contract and the provider's permissions.

Inputs

  • Backup runsLOG
  • Account inventoryCSV
  • Service contractPDF

Processing

Secure AI Agent

Processing the task

  • Read
  • Correlate
  • Verifyrunning
  • Document
Isolated scopeEvidence cited

Output

Completed

Verification prepared

  • Restore tested with evidence
  • Abuse correlated to the account
  • Responsibility boundary documented

Control

You define how far the Agent can act

Different actions can operate with different autonomy levels, and the configuration applies per client.

  1. 1

    Query

    Reads inventory and runs and answers with the evidence.

  2. 2

    Prepare

    Verifies the restore and drafts the abuse reply.

  3. 3

    Request review

    Waits for approval before acting on the account.

  4. 4

    Execute

    Performs the action within the defined limits.

Levels are configured per type of action and per account. Suspending clients, taking down instances, accessing hosted content, and changing production settings always stay under human approval.

Get started

Put a Secure AI Agent to work.

Start on the platform or choose the plan that fits the pace of your operation.

Security and compliance

Security that can be verified.

Certifications and attestations

  • SOC 2 Type II
  • ISO 27001

UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.

Privacy and regulation

LGPD
Operations follow Brazil's Law 13.709/2018. In AI Agent contracts, UPX acts as data processor; the legal basis remains with your company.
Zero Data Retention
A product policy, not a certification: with compatible providers and configurations, processed content is not retained after execution.
Retention and deletion
The retention policy is defined by contract. Once the contract ends, data is deleted within the agreed period.

Frequently asked questions

Common questions about the Cloud and Hosting Agent

What providers usually ask before putting an agent into the operation.

  • What is the difference between tracking backups and testing restores?

    A backup that runs without error proves nothing: recovery is what proves it. The agent tracks the restore test, records what was recovered and how long it took, and flags when the job is green but recovery has never been exercised.
  • Does it access our clients' hosted data?

    Not by default. The content belongs to the client, and the agent's scope covers the control plane — inventory, configuration, job runs, tickets. Access to hosted content is an action under approval, with a record.
  • Does it suspend clients over abuse?

    No. It correlates the indicator with the account, assembles the history, and drafts the reply within the deadline. Suspending or taking down an instance is a human decision, because it interrupts service for a paying customer.
  • How does it handle shared responsibility?

    It documents the boundary the contract defines, service by service, and uses that document when classifying tickets. When the case sits on the client's side, it says so with the clause in hand — instead of improvising the interpretation.
  • Does it flag configuration problems in the environments?

    Yes: ports open to the internet, permissions broader than needed, resources without encryption or without backup. The finding comes with the resource identified, and the fix follows the change process.
  • Is client data used to train models?

    No. Content processed by Secure AI Agents is not used to train UPX models or third-party models.
  • Can we audit what the agent did in each account?

    Yes. Every action is logged per account: what was queried, what was proposed, when, in which system, and under which permission. The history stays available for review and auditing.

Secure AI Agent

Bring a Secure AI Agent to your cloud operation

Talk to our specialists and see how to adapt this AI Agent to your processes, systems, and needs.