Security for a multi-client agency platform.

Separation first. Then the documents procurement actually asks for.

Kuga is built for agencies handling client data, website deployments, lead flows, and AI conversations. This page explains the approach without exposing internal infrastructure. If you need processor terms, start with the DPA.

What this platform has to get right.

The controls that matter when one agency holds many clients.

Account and access

Access is managed through account roles, permissions, and internal need-to-know controls. Customers remain responsible for inviting the right users and protecting credentials.

Client separation

Agency workflows keep client workspaces, deployments, and dashboard access separate so one project does not become an operational tangle.

Communications

Kuga uses appropriate protections for service communications, account operations, support workflows, and customer data handling.

Operational logging

Logs and telemetry may be used to monitor reliability, detect misuse, investigate incidents, and support platform operations.

Abuse prevention

Policies, monitoring, and enforcement help prevent spam, unlawful content, security abuse, data misuse, and unsafe deployments.

Responsible disclosure

Security reports go to security@kuga.ai. Reports should be lawful, safe, non-destructive, and limited to the issue being reported.

Shared responsibility.

Kuga protects the platform. Customers configure the work.

What Kuga handles

  • Platform-level security controls and monitoring
  • Access controls for internal operations
  • Data processing terms and public policy documentation
  • Incident response and abuse investigation where appropriate

What customers handle

  • Accurate client content, lawful collection, and privacy notices
  • Correct account users, roles, and credential protection
  • Safe agent instructions, testing, and human escalation routes
  • Secure third-party systems and integration destinations

Procurement questions, answered here.

So the first email is not a fishing list.

Do you have a DPA?

Yes. Review the Data Processing Addendum, then send remaining procurement questions to legal@kuga.ai or use the contact form.

Where do security reports go?

security@kuga.ai. Keep the first message limited to the issue. Do not send secrets, live credentials, or customer databases.

Are client workspaces separate?

Agency workflows keep client workspaces, deployments, and dashboard access separate. That is the operating unit of the product.

Who writes the end-user privacy notice?

The agency or client. Kuga provides platform privacy, terms, and the DPA. The live agent still needs notices in the deployment context.

Can we get infrastructure diagrams?

This page does not publish internal architecture. For procurement, start with the DPA and privacy policy, then ask legal@kuga.ai for what you still need.

What should customers still own?

Who they invite, what the agent is allowed to say, lawful collection on the client site, and the third-party tools they connect. Kuga protects the platform.

Trust documents.

For procurement and privacy questions.

Sell the service.

Keep the infrastructure.

Create an agency workspace
Start with a client