Promigence Responsible AI & Agent Safety Policy
Effective October 4, 2026 · Last updated October 4, 2026
Purpose. AI agents increasingly write and run code, call tools and act on the internet with little human involvement. Promigence exists to give those agents a safe, fast place to run. This Policy explains how we build our infrastructure responsibly and what we expect from customers who deploy agents on it. It supplements the Acceptable Use Policy and the Promigence Terms of Service.
Section 1: Our commitments#
- Isolation by default. Every sandbox is strongly isolated, designed so that one customer's workload cannot read or affect another's. We treat any isolation failure as a critical security incident.
- Safe defaults and controls. Sandboxes have time limits and resource caps. You can restrict a sandbox's outbound network access to an allow-list of destinations, or cut it off entirely; we recommend doing so for any agent that handles untrusted input.
- Customer data stays the customer's. We do not use code, files, prompts, outputs or other data inside customer sandboxes to train AI models. We access customer data only to provide the Services, to maintain security, to investigate abuse, or as required by law.
- Proportionate monitoring. We monitor infrastructure-level signals, such as network traffic patterns and resource usage, to detect abuse. We do not routinely inspect the contents of customer sandboxes. We review content only when investigating a specific credible report or signal of abuse.
- Kill switches. Our API and command-line tools let customers stop any sandbox or agent immediately. We keep the same ability to contain workloads that threaten the platform or third parties.
- Transparency. We publish our security practices and notify affected customers of material security incidents without undue delay. We may publish periodic information about enforcement actions and government requests.
- Working with the security community. We publish a Vulnerability Disclosure Policy at www.promigence.ai/legal/vulnerability-disclosure and will not pursue legal action against good-faith researchers who follow it.
Section 2: Requirements for customers running autonomous agents#
If you deploy an agent that can make decisions or take actions with limited human involvement, you must:
- Keep a human able to intervene. Maintain the ability to monitor your agents' actions, detect abnormal behavior and stop them. Require human approval before agents take actions that are irreversible or high-impact, such as moving money, deleting production data, sending external communications at scale or changing access permissions.
- Apply least privilege. Give each agent only the network access, credentials, tools and data it needs for its task. Use scoped, short-lived credentials where possible, and do not place long-lived production secrets inside a sandbox when a proxy or broker can inject them instead.
- Control network access. Configure outbound network rules that match the agent's purpose. Treat agents that process untrusted input, such as web pages, emails or user uploads, as potentially compromised by prompt injection, and restrict them accordingly.
- Log and retain. Keep logs of agent actions sufficient to reconstruct what an agent did and why, for at least 90 days or longer if the law requires.
- Test before and during deployment. Evaluate agents for unsafe or unintended behavior before production, and keep testing as models, prompts and tools change.
- Be honest with people. If your agent interacts with people, disclose that it is an AI. Do not let agents impersonate real people or organizations.
- Take extra care with consequential decisions. If your agent's actions can materially affect a person's legal rights, finances, employment, housing, healthcare, education or access to essential services, you must assess the risks, provide meaningful human review and comply with applicable laws, including AI-specific laws such as the EU AI Act and U.S. state AI laws.
- Pass obligations through. If your end users can direct agents on the Services, bind them to terms at least as protective as this Policy and the Acceptable Use Policy.
- Report incidents. Notify us at support@promigence.ai within 72 hours if you discover that an agent on our Services caused, or was used to cause, significant harm to third parties.
Section 3: Shared responsibility#
| Area | Promigence is responsible for | The customer is responsible for |
|---|---|---|
| Isolation | Isolation between customers and the security of the underlying platform | Not attempting to break isolation |
| Network | Providing network controls and abuse detection | Configuring network rules suited to each agent |
| Credentials | Securing platform accounts and API key storage | Protecting API keys and secrets placed in sandboxes |
| Agent behavior | Offering kill switches, logs and limits | What agents do, including autonomous actions and outcomes |
| Data | Protecting data at rest and in transit on our infrastructure | Having the right to process the data their agents handle |
| Legal compliance | Complying with laws that apply to Promigence as a provider | Complying with laws that apply to their use case and end users |
Section 4: Nature of these commitments#
The commitments in this Policy describe how Promigence designs and operates the Services. They are not warranties or guarantees, and they do not create or expand any liability on the part of Promigence. The disclaimers of warranties, the limitation of liability, the indemnification and the security-incident terms of the Promigence Terms of Service, and the responsibility for agents in the Acceptable Use Policy, apply in full to this Policy.
Section 5: Governance#
Promigence's Chief Technology Officer owns this Policy until a dedicated Trust & Safety lead is appointed. We review it at least every six months and after any major incident, product change or new regulation. Questions about this Policy go to support@promigence.ai.