Checklist · Dan Latham · Updated 16 September 2026

Security checklist for agency AI

Kuga separates clients and provides platform controls. The agency still has to invite the right people, approve the right sources, and decide who sees a live conversation.

Security checklist for agency AI

Access

Only people who need the operating workspace have it. Portal users are not agency operators unless you intend that. Remove leavers.

Sources and instructions

Knowledge is approved, not scraped blindly into production. Agent instructions do not ask for secrets or special-category data without a written basis.

When it fails

Handover has an owner. Security issues go to security@kuga.ai, not a public ticket with credentials attached.

Read the security page

Principles and shared responsibility.

UK GDPR for client-facing AIWhite-label AI, under your brandHow agencies should price client AIClient deployment checklist

Sell the service.

Keep the infrastructure.

Create an agency workspace