Agent Journey Lab

Security

What we control today, and what we do not claim.

This page separates deployed controls from work in progress. We list only what a person can check.

Agent Journey Lab does not claim SOC 2, ISO 27001, GDPR compliance, a penetration test, or an uptime SLA.

Start a $199 pilot Discuss multi-site monitoring

Current controls

Controls that are deployed now

Each item below is a current fact about the deployed service.

  • No public control surface

    The website serves pages and one health route. It exposes no job route, no artifact route, no report route, and no admin route. A request for one of those paths returns 404.

  • Provider agents are off in production

    The deployed runner starts in fixture mode. It holds no provider key. The public health route is minimal. It gives a status, a build identifier, and a time. The runner keeps provider readiness in a private in-process record.

  • A start check before any work

    The runner tests itself against a built-in fixture site at start. The runner keeps the result of that check in a private in-process record. The public health route does not give the result.

  • An origin boundary in code

    The runner refuses a target that is not in the approved list for the run. A relative link is resolved first, then checked.

  • Written authorization before form data

    Public research reads public pages only. Form input, submission, sign-in, payment, and any other consequential action need a written scope that names the domains.

  • Evidence outside the web root

    Records are written to a data directory that the web server never maps. There is no path from the public site to a stored record.

  • A declared test identity

    Our public research sessions declare AgentJourneyLab/0.1. We keep the rate low, we respect robots directives, and we stop at a challenge.

  • A site with no third-party code

    This website loads no script, no font, no image, and no file from another host. It sets no cookie and it runs no analytics.

In progress

Controls that we are still building

We publish this list so that a buyer can see the gap. We do not describe how an unfinished control works.

  • Browser isolation for each run, with a stronger sandbox around the browser process.
  • Egress control, so a run can reach only the approved hosts.
  • Resource ceilings for time, memory, and page count in one run.
  • Separate storage for evidence, with encryption at rest and a written retention rule.
  • Supply-chain evidence: pinned dependencies, a build record, and a check before each release.
  • Operations: log review, alerting, backup tests, and a written incident procedure.
  • Privacy and legal work: a data map, a subprocessor list, and a data agreement for customers.

These items are in progress. They are not deployed controls today. We will move an item to the list above when it is deployed and we can show it.

No claim

What we do not claim

Certification
We hold no SOC 2 report and no ISO 27001 certificate.
Compliance
We do not claim GDPR compliance or any other compliance status.
Testing
We have had no external penetration test.
Availability
We offer no uptime SLA and no response time commitment.
Safety
We do not promise that a test cannot affect your systems. That is why we keep a boundary and a written scope.

Disclosure

How to report a security problem

Write to research@agentjourneylab.com with the words security report in the subject. Tell us what you observed and how to see it again.

  • We confirm that we received your message.
  • We do not take legal action against a person who reports a problem in good faith and who does not damage data or service.
  • We ask you to keep the detail private until we make the fix.
  • We have no bug bounty, because we have no budget for one today.

Send a security report

Ask us anything before you buy.

We answer security questions in writing before the pilot starts.

Start a $199 pilot Discuss multi-site monitoring