Announcing CIMD support for MCP Client registration
Learn more

The Security Questionnaire for AI Agent Vendors: Deployment, Residency and Key Custody

Before your agent goes live, what regulated buyers check: a Scalekit security review tray with three checked tiles for deployment, residency and key custody, and the tags where it runs, where data lands, who holds the key.
Nityashree Yadunath
Product Marketing Manager

TL;DR

  • Regulated buyers ask agent vendors three groups of questions that a standard SaaS security questionnaire does not cover: where the integration layer runs, where data lands on each hop of a tool call, and who holds the key to the stored credentials.
  • The integration layer gets the hardest questions because it stores an OAuth token for every app each user connects and executes every tool call.
  • Scalekit's short answers: it runs in your VPC, your customer's infrastructure or air-gapped on Enterprise; the managed service runs in a US or EU region chosen at signup and does not store tool-call payloads; the root key for the token vault can live in your Google Cloud KMS.
  • If your agent product runs on Scalekit, these answers cover the integration layer of your own questionnaire. Each section links to the post with the full explanation.

Where the questions come from

Sell an agent to a bank, a health system, an insurer or a public-sector body and a security review arrives with a questionnaire attached. Most of it is familiar: SOC 2, access control, incident response, vulnerability management. The questions that catch agent vendors are the ones about the agent acting in other apps on behalf of users. That part of the stack, the integration layer, holds a refresh token for every app each user connects and runs every tool call. Reviewers know it, and they ask about it directly.

One tool call through Scalekit, with the three questions regulated buyers ask marked where they land: deployment on the gateway (your VPC, your customer's infrastructure or air-gapped), data residency on the stored data (US or EU region, payloads processed in memory and not stored), and key custody on the token vault (root key in your Google Cloud KMS; revoke Scalekit's access and stored tokens are unreadable to Scalekit).

The questions fall into three groups: deployment, data residency and handling, and key custody. Below is each group, the questions as buyers put them, and the answer Scalekit gives. If your product uses Scalekit for OAuth, the token vault and tool calling, the answers cover that part of your stack. Your model provider, orchestrator and memory stores need their own.

Subject
What the buyer checks
Scalekit's answer
Full post
Deployment
Can the integration layer run inside our boundary, and what still calls out?
Yes, on Enterprise: your VPC, your customer's infrastructure, or air-gapped. Connector traffic goes to the apps. In VPC mode, license and update checks may call out; air-gapped makes no calls to Scalekit.
Data residency
Where does data land on each hop, how long does it stay, and what does the DPA commit to?
US or EU region, chosen at signup. Payloads are processed in memory and not stored. DPA with Standard Contractual Clauses and 30 days' subprocessor notice.
Key custody
Who can decrypt stored credentials, and can we cut that off?
Envelope encryption. The root key can be yours, in Google Cloud KMS. Revoke Scalekit's access and, once the change takes effect, Scalekit cannot decrypt.

Deployment

The buyer is checking whether the integration layer can run inside their boundary and what still calls out if it does. Self-hosted agent integrations: VPC, on-prem and air-gapped has the full explanation of the three modes.

Can your platform run inside our environment?

Yes, on Enterprise, in three modes: in a VPC in your cloud account, in your customer's infrastructure as one isolated instance per customer, or air-gapped. Connections, connected accounts, the token vault, tool execution and Virtual MCP servers all run in your cluster, and credentials, tool calls and logs stay in your network.

What still leaves the network?

Connector traffic. Your instance calls each connector's API and OAuth token endpoint directly, so allow outbound HTTPS to the providers you use. Connectors for apps inside your network need no internet access. There is no telemetry by default. In VPC mode, license validation and update channels may call out; both are configurable and can be routed through your egress controls. In air-gapped mode, no data, logs, metrics or telemetry reach Scalekit.

Where is our data stored in a self-hosted deployment?

In your Postgres instance, inside your deployment: user records, sessions, OAuth tokens and access keys. Scalekit has no database access and no visibility into stored data.

Is the self-hosted product the same as the cloud product?

The SDKs and the REST API work the same way. You point your app at your instance's environment URL and use API credentials from your instance's dashboard. One difference to plan for: Scalekit's shared OAuth app credentials belong to its cloud, so on a self-hosted instance you register your own OAuth app with each provider.

What do we need to run it?

Kubernetes 1.27 or later with Helm, PostgreSQL 15 or later (CockroachDB is supported), Redis 6.2 or later, an SMTP provider, and a domain with a TLS certificate. Docker Compose packaging is available for development, testing and lower-scale deployments. Licensing is per deployment, so each isolated customer instance has its own license key.

Are you a sub-processor when we self-host?

Customer data stays in your deployment, so Scalekit is not in the processing chain for it. If you use the managed service instead, Scalekit is a processor under the DPA and signs a HIPAA Business Associate Agreement on Enterprise.

Data residency and data handling

The buyer is checking where personal data lands on each hop of a tool call, how long it stays, and what the DPA commits to. EU-hosted agent integrations walks one tool call through an EU workspace.

Where is the managed service hosted?

On Google Cloud in two independent regions with no shared application state: US in us-west2 (Los Angeles) and EU in europe-west3 (Frankfurt). You choose the region at signup and the workspace's data stays in it. EU residency is a $99 a month add-on on Growth and included on Enterprise.

Can a workspace move between regions?

No. A workspace and its environments stay in the region chosen at signup. To serve customers in both regions, create a workspace in each.

What do you store from a tool call?

Three things: the user's OAuth tokens and API keys, encrypted and kept until the connected account is deleted; connection settings, including your OAuth app's client secret; and tool-call log metadata. Tool-call inputs and responses are not stored.

Are payloads stored or logged?

No. Request and response payloads are processed in memory for the duration of the call and are not written to Scalekit's database or logs.

What do the logs contain?

Metadata for each tool call: tool name, connection, connected account, identifier, status, error code, duration and time. Successful responses are not logged. An optional setting, Store connector error details, keeps the app's error response for debugging and is off unless you turn it on. Retention is longer and configurable on Enterprise.

Which subprocessors process our data, and how are changes handled?

The list is Schedule A of the DPA, which gives at least 30 days' notice of a new or replaced subprocessor and a right to object on reasonable data-protection grounds. EEA transfers are covered by the EU Standard Contractual Clauses. The standard DPA is available on every plan; a custom DPA is on Enterprise.

Key custody

The buyer is checking who can decrypt the stored credentials and whether they can cut that access off. Bring your own key for agent integrations explains envelope encryption, revocation and rotation in full.

Can the encryption root key live in our KMS?

Yes, in your Google Cloud KMS, on Enterprise. With bring your own key, Scalekit calls your KMS to wrap and unwrap the environment's data key and does not store your root key material.

How are stored credentials encrypted?

With envelope encryption. Credentials are encrypted with AES-256-GCM under a data encryption key that belongs to one environment, and that key is wrapped by a master key in Google Cloud KMS held apart from the database and the application. With BYOK, the master key is yours. Traffic to Scalekit endpoints uses TLS 1.2 or higher.

What happens if we revoke the key?

If the key is disabled or Scalekit's IAM access is revoked, Scalekit cannot encrypt new data or decrypt existing records once the change takes effect, until you restore access. Tool calls that need a stored credential fail, and your Cloud KMS audit logs record the denied requests. If you destroy the key, stored credentials cannot be recovered once destruction completes.

How does key rotation work?

You register a new key, which starts staged. Activating it makes it primary for all new encryption. Re-encrypt Data migrates existing records to the new key on your schedule. Keep the previous key enabled until that completes.

What access does your service account need to our key?

Two IAM roles, granted at the key level: roles/cloudkms.cryptoKeyEncrypterDecrypter and roles/cloudkms.viewer. No broader access is required.

Do tokens ever reach the agent or the model?

By default, no. Scalekit does not return a user’s raw tokens in API responses: your agent calls the tool, and the gateway adds the token to the outgoing request, so tokens stay out of agent code, logs and the model context. If your app needs to call an app with the tokens itself, Scalekit support can turn on credential access for an environment. Once it is on, protecting those tokens in your own code is your responsibility.

Evidence to attach

Questionnaires end with a request for documents. For Scalekit, the set is:

For how Scalekit compares with other agent integration platforms on deployment modes, residency and key custody, see Best self-hosted agent integration platforms.

Questions outside the integration layer

A complete questionnaire also covers the parts of the agent stack that Scalekit does not run. Prepare these from your own architecture:

  • Which model providers you use, the region of each endpoint, and their data-retention terms.
  • Where conversation state, agent memory and vector stores live, and how they are separated per customer and per user.
  • How the agent decides which tools it may call, and which actions need a human approval.
  • How you detect and contain prompt injection that tries to steer the agent toward a write or send action.

Frequently asked questions

What is a vendor security questionnaire?

A structured set of questions a buyer sends a vendor during procurement to assess security, privacy and compliance risk. For AI agent vendors it increasingly covers where the agent runs, what data it stores, and who holds the keys to stored credentials.

What should an AI vendor risk assessment cover for agents?

Beyond standard SaaS controls: deployment options and outbound connections, data residency and retention for each hop of a tool call, subprocessor terms in the DPA, logging of agent actions, and custody of the encryption keys that protect stored OAuth tokens.

Which certifications do buyers expect from an agent integration vendor?

SOC 2 Type II is the baseline. ISO 27001 is common for international and larger buyers. Healthcare buyers require a signed BAA. Scalekit holds SOC 2 Type II and ISO 27001 and signs a BAA on Enterprise.

How do I answer data residency questions for an AI agent?

Answer per hop: where tokens are stored, where tool calls execute, whether payloads are stored, where logs live, and where the model runs. A region name alone does not answer the question.

No items found.
Agent
Auth Quickstart
On this page
Share this article
Agent
Auth Quickstart

Acquire enterprise customers with
‍zero upfront cost.

Every feature unlocked. No hidden fees.