Data residency
All customer data is stored in EU data centers, specifically in Stockholm, Sweden:EU data residency ensures compliance with GDPR and other European data protection regulations. Data does not leave the EU.
Encryption
All communication between components is encrypted. HTTPS is enforced for all endpoints.
Web and API transport hardening
In addition to TLS encryption, Abundly uses security headers across the web portal and API surfaces to reduce browser-based attack risk.CSP is applied on web responses where script and content execution rules matter. API endpoints focus on transport and response hardening headers.
User-generated content isolation
Interactive Apps and HTML documents created by agents can contain arbitrary code. To prevent this code from accessing the main application or its session, the platform serves all rendered user content from a dedicatedusercontent.abundly.ai subdomain that is separate from the main app.abundly.ai domain.
Because the browser treats these as different origins, code running inside an embedded app is fully sandboxed by the browser’s same-origin policy: it cannot read cookies, local storage, or the DOM of the main app, even when displayed inside it. The main app domain refuses to serve the renderer, and the usercontent domain refuses to serve anything else, so the boundary cannot be bypassed by linking or redirecting.
Compliance status
Audit trails
Every agent action is logged with complete context:Audit logs are immutable and cannot be modified or deleted after creation.
- Activity log — Real-time and historical view of agent actions with full details
- Agent diary — High-level summary of what each agent has been doing
- Action history — Append-only log of workspace configuration changes (agents, teams, secrets, API capabilities, workspace settings), scoped to workspace or team admins. See Usage & Limits.
Data retention
System architecture
The platform is built on cloud-native infrastructure:Availability and disaster recovery
We maintain a documented Disaster Recovery Plan covering database recovery, secrets restoration, and service continuity.
Security monitoring
Legal documentation
Privacy Policy
How we collect and use data
Terms of Service
Service agreement and terms
Data Processing Agreement
DPA for enterprise customers
Sub-processors
List of third-party data processors
Enterprise compliance
For enterprise customers, we can provide:- Custom data retention policies
- Dedicated compliance documentation
- Audit support and reports
- Custom DPA terms
Contact Us
Need custom compliance arrangements? Contact our team.

