Agent Trust Data Guard
Control which data an agent can access, join, process and move — including into an external model.
What it does
Capabilities
- Classification from public to regulated, with PII, PHI, PCI, credentials, source code and privileged material called out
- Cross-system combination controls, because access to two datasets separately is not permission to join them
- External model controls over approved providers, permitted data classes, regions, retention and training use
- Egress protection across uploads, API calls, webhooks, prompts, exports and storage writes
What it leaves behind
Evidence produced
- A record of which data classes each agent has actually touched
- A blocked-egress event naming the data class and the destination
Specification
Where this is specified
3 blueprint pages carry the specification for this module.
Data-Loss Prevention
DLP for agents must operate at the point where data crosses tool, model and destination boundaries. It should understand which agent is moving what data, to which destination, under whose authority and for what business purpose.
KEY QUESTION →
Context, Memory & Retrieval Security
Agent memory and retrieval systems can become hidden persistence layers for sensitive data, malicious instructions and stale authority assumptions. Agent Trust Cloud should make memory stores and retrieval sources visible and governable.
RISK →
Privacy, Retention & Data Residency
Agent telemetry may contain prompts, customer records, proprietary code and regulated information. Privacy controls must be configurable from day one, including the ability to operate with metadata-only telemetry for sensitive customers.
PRIVACY BY DESIGN →
13 modules and services make up the platform. See how they fit together.