UseGlic UseGlic
Sign In Get Started
Sign In Get Started

Security Policy

Last updated: August 20, 2026

UseGlic is built for enterprises that require strict isolation, auditability, and governance for AI agent workloads. This Security Policy describes our commitment to protecting your data and the technical and organizational measures we employ.

1. Infrastructure Security

  • Cloud Provider: All infrastructure runs on AWS with SOC 2 Type II compliance.
  • Encryption at Rest: All data is encrypted using AES-256.
  • Encryption in Transit: All communications use TLS 1.2 or higher.
  • Secrets Management: Credentials are stored in AWS SSM Parameter Store with KMS encryption. We never store raw secrets in code, logs, or databases.

2. Sandbox Isolation

Every AI agent runs in an isolated sandbox environment:

  • Dedicated sandbox per agent with no shared filesystems.
  • CPU, memory, process, disk, and runtime limits enforced.
  • No privileged execution or Docker socket mounts.
  • No independent agents share a writable filesystem.
  • Sandbox boundaries are enforced at the infrastructure level.

3. Identity and Access Management

  • Role-Based Access: Four customer roles (Super Admin, Admin, Reader, User) with least-privilege principles.
  • No Long-Lived Credentials: AWS credentials are rotated automatically. No static keys in images or environment files.
  • Scoped IAM Roles: Each runtime has a dedicated IAM role with minimal permissions.
  • Service Tokens: Inter-service communication uses short-lived service tokens, never customer roles.
  • Session Security: Password sessions use HttpOnly, SameSite=Lax cookies. Production cookies are Secure.
  • CSRF Protection: All mutations require valid CSRF tokens.

4. Network Security

  • Deny-by-Default Egress: Sandbox environments have no unrestricted internet access.
  • DNS Control: DNS is controlled and logged. Allowed domains are approved by organization administrators.
  • Blocked Attempts: Unauthorized egress attempts produce alerts.
  • VPC Isolation: Services run in private subnets with VPC endpoints for AWS services.

5. Audit and Compliance

  • Full Audit Trail: Every action is attributable to a user, channel, agent, policy decision, and approval state.
  • AI Model Logging: All model calls log model ID, agent ID, user ID, cost center, and token usage.
  • Immutable Storage: Audit logs use immutable storage to prevent tampering.
  • Network Auditing: Network attempts include source, destination, allow/deny decision, and policy rule.

6. Budget and Resource Controls

  • Every agent has configurable monthly and daily budget limits.
  • Runtime, retry, and tool-call limits are enforced.
  • Agents pause automatically when limits are exceeded.
  • Bot-loop detection prevents runaway agent cycles.

7. Connector Security

  • Encrypted Storage: Credentials stored as AWS SSM SecureString with KMS encryption.
  • No Raw Secrets: APIs and deployment manifests contain references only, never secret values.
  • Approved Connectors: Organizations define which connectors are available. Custom connectors require administrator approval.
  • Runtime Injection: Agents receive environment variable references. Markdown and documentation never include secret values.

8. Production Deployment Gates

The deployment pipeline enforces security requirements before any production deployment:

  • Session-based authentication (no local-dev headers in production).
  • AWS SSM Parameter Store for all secrets.
  • Explicit HTTPS CORS origins (no wildcards).
  • Service tokens delivered via ECS secrets, never in task definitions.
  • Scoped IAM roles with least privilege.

9. Incident Response

  • We maintain an incident response plan for security events.
  • Affected users will be notified within 72 hours of a confirmed breach.
  • We cooperate with law enforcement as required by law.

10. Vulnerability Management

  • Regular vulnerability assessments and dependency scanning.
  • Automated security checks in CI/CD pipeline.
  • We welcome responsible disclosure of security vulnerabilities.

11. Data Processing

  • Data Residency: Data is processed in the region selected during deployment.
  • Data Minimization: We collect only the data necessary to provide the Service.
  • No AI Training on Customer Data: Your data is never used to train models shared with other customers.

12. Limitation of Liability

  • USEGLIC'S TOTAL LIABILITY FOR ANY SECURITY-RELATED CLAIMS SHALL NOT EXCEED ONE HUNDRED US DOLLARS ($100.00).
  • WE ARE NOT LIABLE FOR ANY INDIRECT, INCIDENTAL, OR CONSEQUENTIAL DAMAGES ARISING FROM SECURITY INCIDENTS.
  • THIS LIMITATION APPLIES TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW.

13. Governing Law

  • This Security Policy is governed by the laws of India.
  • All complaints and disputes must be filed exclusively in the courts of Delhi, India (for users outside EEA/UK) or Dublin, Ireland (for users in EEA/UK).
  • You agree to waive any right to file complaints in any other jurisdiction.

14. Contact Us

For security inquiries, vulnerability reports, or to request our SOC 2 report, contact us at:

Email: [email protected]
Website: https://useglic.com

UseGlic UseGlic

The command center for enterprise AI agents.

Company

  • About
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Security Policy

© 2026 UseGlic. All rights reserved.

We use cookies

We use session cookies for authentication and analytics cookies to understand site usage. You can accept or reject non-essential cookies. Privacy Policy