Trust Center

Trust Center

Security, data handling and sub-processor information for AUTOM8LABS products.

Who we are

Legal entityAUTOM8LABS LTD
Company number17073839 (England and Wales)
Registered addressSuite 1 Liberty House, South Liberty Lane, Bristol, BS3 2ST, United Kingdom
ICO registrationZC133046
DevelopmentIn house, United Kingdom. No outsourced development, no third-party access to source code
Security contactsecurity@autom8labs.io

Where your data goes

Our MCP Connectors run on your own workstations and use your own AI subscription. Model data goes to the AI provider you already have a contract with. AUTOM8LABS is not in that path and never receives it.

Your provider's terms apply. Whether data your team sends can be used to train models is governed by your AI provider and the plan your firm uses, not by AUTOM8LABS. Business and enterprise plans generally exclude training. Consumer plans often do not.

What we do receive is limited to licence and version information. Exactly what that means for each product is set out in the data sheets below.

Security framework

  • Code signing. Every binary and installer is signed as AUTOM8LABS LTD through Azure Trusted Signing. Windows verifies publisher identity and file integrity at install time.
  • Dependency management. A CycloneDX Software Bill of Materials is produced per release. Builds fail if any dependency, direct or transitive, carries a known vulnerability. Advisory monitoring runs continuously against our repositories.
  • Source control. All source code is held in private repositories with access restricted to AUTOM8LABS. Development is done in house in the United Kingdom, with no outsourcing and no third-party access to source code.
  • Transport. All communication with AUTOM8LABS services uses HTTPS.

Assurance

ICO registrationHeld, ZC133046
Professional indemnity insuranceHeld
Code signing certificateHeld, AUTOM8LABS LTD via Azure Trusted Signing
ISO 27001Not held
SOC 2Not held
Independent penetration testNot commissioned to date

Sub-processors

Render Services, Inc.Licence server hosting. Licence records. Frankfurt, Germany (EEA)
Stripe, Inc.Card payment processing for website purchases only
Autodesk, Inc.App Store distribution and entitlement checks for store purchases
Google LLCEncrypted off-site backup of licence records

Not a sub-processor: the AI provider used by our MCP Connectors. You choose it, you contract with it directly, and your model data goes to it under that contract rather than ours.

Customers with an active commercial relationship are notified before a new sub-processor that would process their data is added.

Reporting a vulnerability

Send security reports to security@autom8labs.io. Reports are acknowledged within two business days. We ask for a reasonable remediation period before public disclosure.

In scope: the AUTOM8LABS products themselves, their installers, and the AUTOM8LABS services they connect to. Out of scope: configuration of this marketing website, including response headers and mail records; social engineering; denial of service; and automated scanner output with no demonstrated impact.

We do not operate a bug bounty and offer no monetary reward. Reporters who want it are credited.

Security incident notification

Where an issue materially affects customers, affected customers are notified by email without undue delay and in any case within 72 hours of confirmation. Where an incident is a personal data breach notifiable under UK GDPR, we notify the ICO within 72 hours of becoming aware.

Product data sheets

Questions

If your review needs something not covered here, including a completed security questionnaire, please email security@autom8labs.io.

Last reviewed 21 August 2026.