Secure AI Agent · Compliance
AI applied to
the evidence auditors ask for
A specialist configured to gather evidence, keep policies current, and answer security questionnaires based on what the company actually does.
Companies that trust UPX
Capabilities
What the Compliance and Evidence Agent
can do
Main areas of work for the Compliance and Evidence AI Agent in your operation.
Evidence package
Gathers the records that prove each control, in the requested format.
Policy drafting
Writes and updates policies based on what the company actually practices.
Security questionnaires
Answers from existing evidence and flags what is not yet in place.
Control mapping
Relates required controls to what is already implemented.
Gap identification
Points out where evidence is missing before the auditor asks.
Deadline tracking
Monitors periodic reviews and expiry of documents and acceptances.
Skills
Capabilities that compose the specialist
Skills add specific capabilities to the Secure AI Agent according to the processes it needs to execute.
- Evidence assembly
- Gathers and organizes the records that prove each control.
- Questionnaire response
- Answers from the evidence and flags what is missing.
- Policy drafting
- Writes documents aligned with what the company practices.
How it worksFrom control to evidence,
From control to evidence,
with review at every step
Connect your documentation sources, define what the agent can do, and let the package assembly happen within your company's limits.
- Connect documentation and systems
- The agent works with what is already recorded.Connect the document base, the identity provider, and the ticket tracker so the Secure AI Agent has access only to what it needs to assemble each package.
- Ask for the work
- Talk to the agent in natural language.Request the evidence package, a policy update, or a questionnaire response through the available channels. The agent understands the context, applies the configured skills, and follows the criteria your company defines.
- The agent assembles. You validate.
- From control to submission, with control.The agent gathers, drafts, and organizes within the defined permissions. Sending to the auditor or customer and validating the content stay with whoever owns the process.
01
02
03
Integrations
Connected to the sources where your evidence already lives
The Compliance and Evidence AI Agent can query your documentation and run tasks in the systems your team already uses.

Confluence 
Okta
Flow
What goes in,
what the agent does, and what comes out
From the required control to a ready package, following your company's rules and permissions.
Inputs
- Received questionnaireDOC
- Current policyPDF
- Control recordCSV
Processing
Secure AI Agent
Processing the task
- Read
- Map
- Gatherrunning
- Draft
Skill appliedControls verified
Output
Completed
Package prepared
- Controls mapped
- Evidence referenced
- Gaps flagged
Control
You define how far the Agent can act
Different actions can operate with different autonomy levels, always within your company's rules.
- 1
Query
Reads documents and records and answers with the reference.
- 2
Prepare
Assembles the package and drafts the response.
- 3
Request review
Waits for validation from the process owner.
- 4
Execute
Performs the action within the defined limits.
Levels are configured per type of action, according to each company's policy. Publishing a policy and sending responses to auditors or customers always stay under human approval.
Get started
Put a Secure AI Agent to work.
Start on the platform or choose the plan that fits the pace of your operation.
Security and compliance
Security that can be verified.
Certifications and attestations
UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.
Privacy and regulation
- LGPD
- Operations follow Brazil's Law 13.709/2018. In AI Agent contracts, UPX acts as data processor; the legal basis remains with your company.
- Zero Data Retention
- A product policy, not a certification: with compatible providers and configurations, processed content is not retained after execution.
- Retention and deletion
- The retention policy is defined by contract. Once the contract ends, data is deleted within the agreed period.
Frequently asked questions
Common questions about the Compliance and Evidence Agent
What teams usually ask before putting an agent to support audits and compliance.
Does the agent certify the company for ISO 27001?
No. Certification is issued by an accredited certification body. The agent organizes evidence, maintains policies, and prepares the company for the audit, but does not replace the auditor or the certifier.Does it answer questionnaires we cannot back up?
No. The agent answers from existing evidence and explicitly flags when a control is not implemented or has no record. The gap becomes a finding, not an invented answer.Can the policies it writes be used as-is?
They are a first version based on what the company practices and what the records show. Final review and approval stay with the process owner, because the policy must reflect the reality of the operation.Does it send responses to the customer or auditor?
Not by default. Publishing a policy and sending responses stay under human approval. The agent leaves the material ready for review by whoever signs it.Are our documents used to train models?
No. Content processed by Secure AI Agents is not used to train UPX models or third-party models.Can we audit what the agent did?
Yes. Every action is logged: what was queried, what was proposed, when, in which system, and under which permission. The history stays available for review and auditing.How long does it take to go live?
It depends on the framework involved and where the documentation lives. The starting point is connecting the document base and mapping the controls for the first cycle.
Secure AI Agent
Bring a Secure AI Agent to your compliance program
Talk to our specialists and see how to adapt this AI Agent to your processes, systems, and needs.















