Secure by default

Secure AI Agents are not an adjective. They are architecture.

AI agents access data and systems, and they can execute actions. That is why security, access control, and governance are part of the operation from the start.

Cybersecurity DNA

UPX did not start with AI. It started by protecting critical operations.

That experience shapes the architecture of Secure AI Agents: if an agent can access real systems, its access is treated with the same rigor as a privileged credential.

  • More than 20 years in critical operations

    Banks, fintechs, carriers, and data centers — environments that cannot stop.

  • In-house SOC, 24/7/365

    Our own operation, no outsourcing. Whoever operates is accountable.

  • Access as a privileged credential

    An agent's access to a real system gets the same treatment as a privileged account.

  • Engineering before product

    The controls on this page exist because they were already operational practice, not because they became a feature.

Security architecture

Control at every layer of the operation

From identity to execution, each agent operates within the access, rules, and limits defined for its role.

  • Identity and access

    SSO and authentication
    Access control integrated with your corporate identity.
    MFA
    An additional layer of protection for platform access.
    Per-agent permissions
    Each agent operates only with the access its role requires.
  • Data and security

    Zero Data Retention
    Reduced data retention in interactions with compatible models.
    Encryption
    Data protected in transit and at rest.
    Isolated environment
    Each agent runs in its own environment, reducing lateral access to other contexts.
  • Governance

    Human approval
    Sensitive actions can require approval before execution.
    Traceability
    Actions and executions keep records for follow-up.
    Guardrails
    Rules and limits define what each agent can access and execute.

Three decisions that come before any task.

Deny by default

The agent inherits no access. Every system, data set, and action must be granted for the role it performs.

Separate execution from decision

The agent prepares the work; authority over higher-impact actions stays with your company.

Log in order to review

Without records there is no governance. Executions keep history for follow-up and later analysis.

Zero Data Retention

Processes. Delivers. Does not store.

When providers, models, and configurations compatible with Zero Data Retention are used, the processed content is not retained by the provider after execution. Coverage depends on the provider and on how the flow is configured — it is not an automatic property of every integration.

  1. 01 / Receives

    The data enters the flow

    The agent receives only the data required for the task.

  2. 02 / Processes

    The task is executed

    The data is used during execution.

  3. 03 / Discards

    The content does not remain

    In ZDR-compatible configurations, the content is not retained by the provider after processing.

Human-in-the-loop

Critical actions go through you.

Not every task needs the same level of autonomy. Your company defines when the agent can execute and when an action requires human approval.

Controlled access

The agent accesses what it needs. Nothing beyond that.

The data, systems, tools, and actions available are defined according to each Secure AI Agent's role.

  • Read emails from the authorized accountAllowed
  • Query entries in the ERPAllowed
  • Issue a payment to a supplierRequires approval
  • Delete recordsBlocked
Operational visibility

You know what the agent did.

Executions can be followed to give visibility over the actions, approvals, and results of the operation.

Monitoring
Follow-up on how the agents operate.
Traceability
History of actions and executions.
Audit
Records that support analysis and governance of the operation.
14:32:08ERP queryFinance AgentSuccess
14:32:17Payment requestFinance AgentApproval
14:35:42Payment authorizedFinance managerApproved
Security and compliance

Security that can be verified.

Certifications and attestations

  • SOC 2 Type II
  • ISO 27001

UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.

Privacy and regulation

LGPD
Operations follow Brazil's Law 13.709/2018. In AI Agent contracts, UPX acts as data processor; the legal basis remains with your company.
Zero Data Retention
A product policy, not a certification: with compatible providers and configurations, processed content is not retained after execution.
Retention and deletion
The retention policy is defined by contract. Once the contract ends, data is deleted within the agreed period.
Cybersecurity DNA

AI to operate. Security to trust.

UPX Secure AI Agents combine execution, control, and the experience of a company that has protected critical operations for more than 20 years.