Trust centre

What stops an agent doing something irreversible?

A gate it cannot open on its own. This page explains what the gate is, who holds the key, and what we will and will not claim.

The six rules we build to

Six rules, in plain English.

  1. The agent never holds live credentials.
  2. The sandbox and live get the identical change.
  3. Every change is a named, retryable step.
  4. Nothing goes live without green gates and a recorded approval.
  5. Budget is reserved before any AI work.
  6. Our own code never runs inside an AGPL-licensed process.
Four numbers

Four numbers that must always read the same.

1service holds live-site credentials
0AI calls in the rollback path
0governance records edited or deleted
0writes to live outside the Promoter
Data in India

Your data and logs stay in India.

Server racks with status lights in a data centre
Hosted in Mumbai (ap-south-1)
Hosting regionap-south-1 (Mumbai)
BackupsHeld in India
Security logs180 days, in India, per CERT-In
DPDPEvery request logs who asked and for what purpose
Prompt safety

Your data is data, not instructions.

Text inside your ERP (a customer name, an item description) can never instruct the agent or widen what it may touch. The plan fixes the allowed tools before any customer data is read.

Architecture

How rung1 is built: 4 planes, 1 route to live.

The agent works in the sandbox. Only the Promoter can reach your live ERP, and only with a signed approval.

Swipe to see the full diagram →

rung1 architecture Four planes. The request plane feeds the agent plane, which writes only to the sandbox. The governance plane runs gates and records approval. Only the Promoter, highlighted, writes to the live ERP. 01 · REQUEST02 · AGENT03 · GOVERNANCE04 · LIVE Console · WhatsApp Budget reserved Actor + purpose log Site snapshot Plan + tool scopes Sandbox (writes) Gates G1–G7 Diff + approval Append-only record Your live ERP Promoter the only route to live
Simplified. Clay marks the only route to your live ERP.
Security and access

Who can touch what.

Credentials

Live-site credentials are held by one service, the Promoter, and used for one signed change at a time.

Tool scopes

The agent reaches ERPNext only through a fixed set of tools. The plan picks which ones before any data is read.

Records

Governance records are append-only. They cannot be edited or deleted, including by us.

Open-source licences we run

Every app, its licence, and the version we pin.

AppUpstream projectLicencePinned version
ERPERPNext + India ComplianceGPL-3.0Published at launch
HR and India PayrollFrappe HRGPL-3.0Published at launch
FrameworkFrappe FrameworkMITPublished at launch

Licences move. We re-verify each one before publishing.

Certifications

We only list what we hold.

rung1 does not yet hold SOC 2 or ISO 27001. When an audit is in progress, it will be shown here as “In progress” with a target date. Until then, the rules and numbers above are what we stand behind.

Frequently asked questions

Questions about security.

Still have a question? Book a working session and ask us directly.

Does rung1 train AI models on my business data?

No. Customer data is not used to train AI models. The model is used only to plan and build the change you asked for, inside a sandbox copy of your site.

Can the AI agent delete data from my ERP?

Not on its own. Deletions and other irreversible changes always need a named person, on every rung of the autonomy ladder. The agent also never holds the credentials to your live ERP.

Is rung1 SOC 2 or ISO 27001 certified?

Not yet. We list only certifications we hold. When an audit is in progress it will be shown on the trust centre with a target date.

Ask us the hard questions.

Book a working session Contact us