Deny by default
The agent inherits no access. Every system, data set, and action must be granted for the role it performs.
AI agents access data and systems, and they can execute actions. That is why security, access control, and governance are part of the operation from the start.
Cybersecurity DNA
That experience shapes the architecture of Secure AI Agents: if an agent can access real systems, its access is treated with the same rigor as a privileged credential.
Banks, fintechs, carriers, and data centers — environments that cannot stop.
Our own operation, no outsourcing. Whoever operates is accountable.
An agent's access to a real system gets the same treatment as a privileged account.
The controls on this page exist because they were already operational practice, not because they became a feature.
From identity to execution, each agent operates within the access, rules, and limits defined for its role.
Identity and access
Data and security
Governance
The agent inherits no access. Every system, data set, and action must be granted for the role it performs.
The agent prepares the work; authority over higher-impact actions stays with your company.
Without records there is no governance. Executions keep history for follow-up and later analysis.
When providers, models, and configurations compatible with Zero Data Retention are used, the processed content is not retained by the provider after execution. Coverage depends on the provider and on how the flow is configured — it is not an automatic property of every integration.
01 / Receives
The agent receives only the data required for the task.
02 / Processes
The data is used during execution.
03 / Discards
In ZDR-compatible configurations, the content is not retained by the provider after processing.
Not every task needs the same level of autonomy. Your company defines when the agent can execute and when an action requires human approval.
The data, systems, tools, and actions available are defined according to each Secure AI Agent's role.
Executions can be followed to give visibility over the actions, approvals, and results of the operation.
| Time | Action | Origin | Result |
|---|---|---|---|
| 14:32:08 | ERP query | Finance Agent | Success |
| 14:32:17 | Payment request | Finance Agent | Approval |
| 14:35:42 | Payment authorized | Finance manager | Approved |
Certifications and attestations


UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.
Privacy and regulation
UPX Secure AI Agents combine execution, control, and the experience of a company that has protected critical operations for more than 20 years.