What stops an agent doing something irreversible?
A gate it cannot open on its own. This page explains what the gate is, who holds the key, and what we will and will not claim.
Six rules, in plain English.
- The agent never holds live credentials.
- The sandbox and live get the identical change.
- Every change is a named, retryable step.
- Nothing goes live without green gates and a recorded approval.
- Budget is reserved before any AI work.
- Our own code never runs inside an AGPL-licensed process.
Four numbers that must always read the same.
Your data and logs stay in India.
| Hosting region | ap-south-1 (Mumbai) |
|---|---|
| Backups | Held in India |
| Security logs | 180 days, in India, per CERT-In |
| DPDP | Every request logs who asked and for what purpose |
Your data is data, not instructions.
Text inside your ERP (a customer name, an item description) can never instruct the agent or widen what it may touch. The plan fixes the allowed tools before any customer data is read.
How rung1 is built: 4 planes, 1 route to live.
The agent works in the sandbox. Only the Promoter can reach your live ERP, and only with a signed approval.
Swipe to see the full diagram →
Who can touch what.
Credentials
Live-site credentials are held by one service, the Promoter, and used for one signed change at a time.
Tool scopes
The agent reaches ERPNext only through a fixed set of tools. The plan picks which ones before any data is read.
Records
Governance records are append-only. They cannot be edited or deleted, including by us.
Every app, its licence, and the version we pin.
| App | Upstream project | Licence | Pinned version |
|---|---|---|---|
| ERP | ERPNext + India Compliance | GPL-3.0 | Published at launch |
| HR and India Payroll | Frappe HR | GPL-3.0 | Published at launch |
| Framework | Frappe Framework | MIT | Published at launch |
Licences move. We re-verify each one before publishing.
We only list what we hold.
rung1 does not yet hold SOC 2 or ISO 27001. When an audit is in progress, it will be shown here as “In progress” with a target date. Until then, the rules and numbers above are what we stand behind.
Questions about security.
Still have a question? Book a working session and ask us directly.
Does rung1 train AI models on my business data?
No. Customer data is not used to train AI models. The model is used only to plan and build the change you asked for, inside a sandbox copy of your site.
Can the AI agent delete data from my ERP?
Not on its own. Deletions and other irreversible changes always need a named person, on every rung of the autonomy ladder. The agent also never holds the credentials to your live ERP.
Is rung1 SOC 2 or ISO 27001 certified?
Not yet. We list only certifications we hold. When an audit is in progress it will be shown on the trust centre with a target date.