Privacy
What we collect, and what leaves our infrastructure
AgentScore runs a release gate against an AI agent you point us at. That means we hold your agent's credentials and its answers. This page says exactly what that involves.
Last updated 2026-08-22 · English is the authoritative version
Who processes your data
AgentScore is an independent release gate for AI agents. Questions, access requests and deletion requests go to ceo@labs67.com, and are answered by a person, not a queue. Registered company details are provided on request and before any data processing agreement is signed.
What we collect
Only what a run needs. There is no analytics vendor, no advertising network and no third-party tracker on the application.
- Account
- Your email address and an opaque user identifier, both from our sign-in provider.
- Agent configuration
- The name you gave the agent, its endpoint URL, the request template and the path to the answer in its response.
- Agent credentials
- Whatever headers your endpoint requires — typically an API key. Encrypted at rest with AES-256-GCM, and never returned by any part of the interface or the API, including to you. They can be replaced or cleared, not read back.
- Run data
- The answers your agent gave to our test prompts, the per-case scores, and the verdict. The prompts themselves are ours, from a published case bank — we do not collect or replay your own traffic.
- Billing
- Your point balance and a ledger of what was reserved, spent and refunded. Card details are handled by Stripe and never reach us.
What your agent sends us, and what we do with it
This is the part worth reading twice. To grade an answer we send it to a judge model we do not host — currently Google's Gemini API. If your agent is connected to production data, its answers to our prompts may contain that data, and that data will leave our infrastructure.
So: connect a staging endpoint, or an endpoint pointed at synthetic data, unless you are content for the answers to be graded by a third-party model. We say this on the setup screen as well as here, because it is the one decision a customer can get wrong in a way we cannot undo for them.
Who else sees it
- Google (Gemini API)
- Grades answers. Receives our test prompts and the responses your agent gave them. Receives no credentials, no account data and no billing data.
- DigitalOcean (Frankfurt, Germany)
- Hosts the backend and the database. All run data, verdicts and encrypted credentials are stored here.
- Vercel
- Serves the web interface. Handles page requests; does not hold run data or credentials.
- Clerk
- Handles sign-in. Holds your email and authentication state.
- Stripe
- Handles card payments. Card details go directly to Stripe and never reach our servers or our database.
We do not sell data, and we do not share it with anyone not on this list. If the list changes, this page changes with it.
How long we keep it
- Your agent's answers
- 90 days from the end of the run, then automatically replaced with a marker. The raw text, the execution trace and the per-case evidence excerpt all go.
- Scores, verdicts and attestations
- Kept. An attestation is a receipt somebody may have attached to a contract, and it has to keep verifying after the evidence behind it has expired.
- Billing ledger
- Kept. It is an append-only financial record, and it survives account deletion for the same reason an invoice does.
- Agent credentials
- Until you replace or clear them, or delete the agent.
Deleting your account
Deleting your account removes your ability to sign in and stops any credential we hold from being usable. Your billing history is retained, as above. Anything else you want removed, write to ceo@labs67.com and say what — we will tell you what we can delete and what we cannot, and why.
What this page is not
- It is not a certification of anything, ours or yours.
- It is not legal advice, and it does not create obligations beyond those in the terms.
- It describes the system as it is today. Where a protection is partial, it says so rather than rounding up.