AgentScore

Data processing

Roles, sub-processors, transfers and retention

The disclosure your legal team needs before a data processing agreement can be drafted. It states one thing plainly that most vendors bury: grading sends your agent's answers to a model we do not host.

Last updated 2026-08-22 · English is the authoritative version

What this document is

This is a disclosure, not a signed agreement. It states the facts your legal team needs in order to draft or review one, so the first call is about terms rather than about what we actually do. To sign a data processing agreement, write to ceo@labs67.com — we will work from your paper or ours.

Roles

You
Controller of any personal data reachable through the agent endpoint you connect.
AgentScore
Processor of that data, acting on your documented instruction — which is: run the release gate you selected, against the endpoint you supplied.
AgentScore, separately
Controller of your own account data: your email, your billing ledger and your run history as an account holder.

Categories of data, and where they come from

We do not collect personal data about your end users directly, and we do not replay your production traffic. Personal data reaches us in one way only: your agent includes it in an answer to one of our test prompts.

Data subjects
Your account users, and any individual whose data your agent discloses in an answer.
Categories
Account email and authentication state; agent configuration; agent endpoint credentials; the text of your agent's answers, which may contain whatever your agent has access to.
Special categories
None requested, none required, and none knowingly processed. If your agent can disclose them, it can disclose them into an answer — which is the reason to connect a staging endpoint.

Sub-processors

Google (Gemini API)
Grades answers. Receives our test prompts and the responses your agent gave them. Receives no credentials, no account data and no billing data.
DigitalOcean (Frankfurt, Germany)
Hosts the backend and the database. All run data, verdicts and encrypted credentials are stored here.
Vercel
Serves the web interface. Handles page requests; does not hold run data or credentials.
Clerk
Handles sign-in. Holds your email and authentication state.
Stripe
Handles card payments. Card details go directly to Stripe and never reach our servers or our database.

The judge is the transfer that matters and the one to raise with your team first: grading an answer requires sending it to a model we do not host. There is no configuration that avoids this today. An in-perimeter judge is what the enterprise engagement exists for.

Location and transfers

  • Run data, verdicts and encrypted credentials are stored in Frankfurt, Germany.
  • Sign-in, payments, page serving and grading are performed by the providers listed above, which process outside the EU. Each is engaged under its own standard contractual terms.

Security measures

  • Endpoint credentials encrypted at rest with AES-256-GCM, with the key held outside the database and never returned by any interface.
  • Authentication on every owner-scoped endpoint, with row-level scoping to the owning account.
  • Database and cache unreachable from the internet.
  • Structural redaction of captured text before it is displayed anywhere, including to our own administrators.
  • The full list, including what we have not done, is on the security page.

Retention and deletion

Agent answers and traces
Automatically erased 90 days after the run ends. This is the personal-data-bearing category, and it is the one with an automatic clock on it.
Scores, verdicts, attestations
Retained. They carry no answer text, and an attestation must keep verifying for as long as somebody may rely on it.
Billing ledger
Retained as a financial record, including after account deletion.
On request
Earlier erasure of a specific run or agent: write to ceo@labs67.com naming it.

Assisting you

  • Data subject requests: tell us the run or the agent and we will locate and erase the relevant records.
  • Breach notification: we will tell you without undue delay, with what we know at the time rather than after we have finished investigating.
  • Audit: we will answer a security questionnaire and walk your team through the system. We do not currently hold a third-party audit report, and we will not imply that we do.