> For the complete documentation index, see [llms.txt](https://docs.uprightplatform.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.uprightplatform.com/appendix/upright-agent-security-addendum.md).

# Upright Agent Security Addendum

*Last updated: 24 June 2026*

## 1. System overview

The Upright Agent is a conversational interface on the Upright Platform, also accessible in Claude and Microsoft Copilot via an MCP connector. The agent uses generative AI to answer questions over data available on the Upright Platform.

## 2. Data processing, residency and subprocessors

The Upright Agent processes user-provided data (prompts, uploaded files) and data made available by Upright on the Upright Platform.

The Upright Platform is hosted on AWS, with primary location in Dublin, Ireland. The Upright Agent currently uses the following LLMs to provide its functionality:

* Anthropic Claude, via Anthropic API or AWS Bedrock for EU data residency
* HuggingFace (for Leena-2, Upright's vertically trained LLM)

## 3. Usage of data for training Large Language Models

User-provided data is not used to train large language models.

## 4. Data retention

Data is retained according to Upright's Data Retention and Disposal Policy (available on request). Upon a deletion request from a current or former customer, Upright disposes of the data within 90 days (or per the customer's agreement). Upright may keep the minimum data necessary to meet legal obligations, resolve disputes, and enforce agreements.

## 5. Access control

Upright Agent is limited to the data the user has access to, using Upright Platform access controls. Access controls are governed by Upright's Access Control and Termination Policy (available on request).

## 6. Change management

Changes to the Upright Agent are implemented according to Upright's Change Management Policy (available on request).

## 7. EU GDPR and EU AI Act compliance

Upright Project is committed to complying with applicable AI legislation, including EU GDPR and EU AI Act (EU 2024/1689). As a limited-risk AI provider, Upright complies with the transparency obligations set out in Article 50. More information is available on Upright's [privacy policy](https://www.uprightproject.com/privacy-policy/).

## 8. Opt-out

The Upright Agent can be disabled per account on request.

{% hint style="info" %}
For more on how the Upright Agent's scope and data handling work in practice, see [Limits and confidentiality](/upright-agent/limits-and-confidentiality.md).
{% endhint %}
