Skip to main content
Abundly is built on enterprise-grade cloud infrastructure with security and compliance at its foundation. All data is stored in EU data centers, encrypted at rest and in transit, and protected by comprehensive access controls. This page provides the technical details enterprise security teams need.

Data residency

All customer data is stored in EU data centers, specifically in Stockholm, Sweden:
EU data residency ensures compliance with GDPR and other European data protection regulations. Data does not leave the EU.

Encryption

All communication between components is encrypted. HTTPS is enforced for all endpoints.

Web and API transport hardening

In addition to TLS encryption, Abundly uses security headers across the web portal and API surfaces to reduce browser-based attack risk.
CSP is applied on web responses where script and content execution rules matter. API endpoints focus on transport and response hardening headers.

User-generated content isolation

Interactive Apps and HTML documents created by agents can contain arbitrary code. To prevent this code from accessing the main application or its session, the platform serves all rendered user content from a dedicated usercontent.abundly.ai subdomain that is separate from the main app.abundly.ai domain. Because the browser treats these as different origins, code running inside an embedded app is fully sandboxed by the browser’s same-origin policy: it cannot read cookies, local storage, or the DOM of the main app, even when displayed inside it. The main app domain refuses to serve the renderer, and the usercontent domain refuses to serve anything else, so the boundary cannot be bypassed by linking or redirecting.

Compliance status

Audit trails

Every agent action is logged with complete context:
Audit logs are immutable and cannot be modified or deleted after creation.
You can access audit information through:
  • Activity log — Real-time and historical view of agent actions with full details
  • Agent diary — High-level summary of what each agent has been doing
  • Action history — Append-only log of workspace configuration changes (agents, teams, secrets, API capabilities, workspace settings), scoped to workspace or team admins. See Usage & Limits.
See Activity Monitoring for details on using these tools.

Data retention

System architecture

The platform is built on cloud-native infrastructure:

Availability and disaster recovery

We maintain a documented Disaster Recovery Plan covering database recovery, secrets restoration, and service continuity.

Security monitoring

Privacy Policy

How we collect and use data

Terms of Service

Service agreement and terms

Data Processing Agreement

DPA for enterprise customers

Sub-processors

List of third-party data processors

Enterprise compliance

For enterprise customers, we can provide:
  • Custom data retention policies
  • Dedicated compliance documentation
  • Audit support and reports
  • Custom DPA terms

Contact Us

Need custom compliance arrangements? Contact our team.