Trust Center

How Bench protects your data

Bench is a multi-tenant SaaS product built on Google Cloud. This page is our public record of how the product is architected, operated, and controlled — honest about what is in place and what we are still building.

Current security posture

A direct view of what is live today and what remains in progress.

Hosted on Google Cloud — US, us-east4

Live

All cloud infrastructure and Firestore records run in Google Cloud region us-east4, United States.

SOC 2 readiness

In progress

We are building the controls and evidence base required for a SOC 2 Type II audit.

ISO 27001 program

In progress

An information security management program aligned to ISO 27001 is in progress.

Cyber / E&O insurance

In progress

Cyber liability and errors & omissions insurance is in process.

Bench does not currently hold SOC 2 Type II or ISO 27001 certification.

How we manage risk

These controls describe the boundaries and practices currently in place across the Bench service.

Infrastructure

Google Cloud, US region

All cloud application logic, tenant data, and Firestore records run on Google Cloud in us-east4 (United States). Sub-processor residency details are in the Sub-processors section of this page.

Encryption in transit

Traffic between clients and Bench cloud services uses TLS. Firebase SDK connections are encrypted in transit with Google-managed certificates.

Multi-tenant instance scoping

Each customer account is scoped to a distinct tenant instance. Application logic and Firestore security rules enforce that one tenant cannot read or write another tenant’s records.

Data & privacy

US data processing

Customer data is processed in the United States. The current list of sub-processors — including AI model providers — is published in the Sub-processors section below.

Data export and deletion

Rights to export or delete customer data are defined in the Data Processing Agreement (DPA). Submit a request through the DPA process or via the contact form at /contact.

Mac agent runtime — shared responsibility

The Bench AI-agent runtime runs on Mac hardware that your organization owns and manages. Your team controls the hardware, operating-system access, local credentials, physical security, and runtime availability. Bench controls the cloud endpoints and the tenant-scoped permissions the runtime uses. Data or credentials placed on the customer Mac cross from the Bench cloud boundary into your security boundary and are not protected by Bench-hosted infrastructure controls after that transfer.

Product & application

Human approval for external agent communications

Before any agent-generated communication is sent outside Bench, a human must review and approve it. The agent cannot send external messages autonomously.

No agent-initiated payments

Agents cannot initiate, authorize, or submit financial transactions. Payment actions require explicit human action.

AI action audit log

Agent actions that generate or send external communications are logged with a trace ID, provider message ID, AI-generated flag, prompt used, and triggering user. See the AI Transparency page for the full schema.

Organizational

Commercial terms

Customer agreements — including the Self-Service Subscription Terms accepted at checkout and the Data Processing Agreement — are with Bench (BenchAGI). The DPA and Privacy Policy are linked in the Policies section of this page; subscription terms are presented at checkout.

Incident response

Security incidents follow a documented incident response and takedown process. Bench records each report, its severity, affected tenants, containment actions, remediation owner, and closure evidence.

Third-party model dependency

Bench routes AI tasks to third-party model providers (listed in Sub-processors). Bench does not own or operate any AI foundation model. Output accuracy depends on the model provider and the inputs provided.

Operations

Always-current SaaS — no version matrix

Bench supports the production service and the current customer-managed runtime release. There is no separate supported-version matrix. Apply runtime updates through the supported distribution path.

Vulnerability reporting

Report suspected vulnerabilities through the contact form at /contact?topic=security. Include the affected surface, reproduction steps, impact, and any known mitigations. Do not include secrets or customer data in a public issue.

Legal reference

Sub-processors

Bench uses the third-party sub-processors listed below to process customer personal data in connection with the Bench platform. This list is the public sub-processor inventory referenced by the Data Processing Agreement (DPA) and the customer subscription terms. See also the Data Processing Agreement and Data Processing Agreement.

Bench will provide notice of new sub-processors (other than AI Model Providers, which may change with advance notice as described in the DPA) at least thirty (30) days before the new sub-processor begins processing customer personal data. Notice may be given by updating this list and/or by email.

Current sub-processors

As of 2026-07-15. Entity names are the legal contracting parties used by each provider in their public terms, where available.

Sub-processorCategory and purposeProcessing location
Anthropic, PBC (Claude)AI Model Provider; AI inference for Agent functionalityUnited States
OpenAI, L.L.C.AI Model Provider; supplementary AI inferenceUnited States
X.AI LLC (Grok)AI Model Provider; AI inference for Agent functionalityUnited States
Google LLC (Google Cloud Platform)Cloud hosting and storage (Firestore; Google Cloud Storage)United States (us-east4)
Stripe, Inc.Payment processing for subscription billingUnited States

Notes

  • Local open-source models that run on the customer-owned Gateway (for example, models accessed through Ollama for functions such as text embeddings) operate on the customer’s host machine and are not third-party sub-processors.
  • Card numbers and other payment credentials are processed by Stripe; Bench does not store full payment card numbers.
  • For how Bench handles personal data more generally, see the Privacy Policy.

Questions about this list or a data-protection objection under the DPA? Write to privacy@benchagi.com or legal@benchagi.com.

Share this section: /trust#subprocessors

Frequently asked questions

Where is my data hosted?

Customer data is hosted on Google Cloud in us-east4 (United States). The current list of sub-processors — including AI model providers who may process data — is on this page under Sub-processors.

Who is responsible for the Bench Mac agent runtime?

The Bench AI-agent runtime runs on Mac hardware your organization owns and manages. Your team controls the hardware, operating-system access, local credentials, physical security, and runtime availability. Bench controls the cloud endpoints and the tenant-scoped permissions the runtime uses. Data or credentials placed on the customer Mac cross from the Bench cloud boundary into your security boundary and are not protected by Bench-hosted infrastructure controls after that transfer.

How do I export or delete our data?

Data export and deletion rights are defined in the Data Processing Agreement (DPA). Submit a request through the DPA process or via the contact form at /contact.

How do I report a security vulnerability?

Use the contact form at /contact?topic=security. Include the affected surface, steps to reproduce, impact, and any known mitigations. We aim to acknowledge reports within 2 business days and complete initial triage within 5 business days. These are operating targets, not contractual commitments.

What is Bench’s certification status?

Bench does not currently hold SOC 2 Type II or ISO 27001 certification. We are building the controls and evidence base required for SOC 2 readiness, and an ISO 27001-aligned information security program is in progress. This page will be updated when that status changes.

What are your response time targets for security issues?

These are operating targets, not contractual service-level commitments: acknowledge a report within 2 business days; complete initial triage within 5 business days; provide status updates when material facts or remediation timing change; coordinate disclosure timing with the reporter when a fix requires customer action.

Can a Bench agent send emails or make payments without human approval?

No. Any agent-generated communication to a party outside Bench requires a human to review and approve it before it is sent. Agents cannot initiate, authorize, or submit financial transactions — payment actions require explicit human action.

Security questions or a vendor questionnaire?

Use the contact form and mention Security in your message. We review every inquiry and route it to the right person on the Bench team.