Keyv npm Supply-Chain Compromise
Deputy Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Overview

Welcome to Deputy's Trust Center. Our commitment to data privacy and security is embedded in every part of our business. Use this Trust Center to learn about our security posture and request access to our security documentation.
Knowledge Base (FAQ)
  • Can Deputy AI act on its own without my initiation or approval?
  • Does Deputy AI respect my existing user permissions?
  • What employee data does Deputy AI access to perform its tasks?
  • What happens if Deputy AI makes a mistake?
  • How does Deputy segregate customer data from other clients?
View more

Trust Center Updates

Keyv npm Supply-Chain Compromise

Copy link
Vulnerabilities

On August 4, 2026, several npm packages in the keyv/cacheable ecosystem were compromised, resulting in the publication of malicious package versions.

Deputy has assessed its dependencies and build systems and confirmed that no affected package versions were introduced into our environment. Our systems and customer data have not been impacted by the events.

As this campaign is still developing, we are continuing to monitor published indicators and will update this notice if our assessment changes.

New SOC2 Type 2 report available

Compliance

We are pleased to announce the successful completion of our latest SOC 2 assessment and the receipt of our official attestation report. You may now request a copy of the new report directly through this Trust Center.

Deputy not impacted by React Framework

Vulnerabilities

Deputy is aware of the recently announced critical vulnerability affecting the React framework and React Server Components (RSC). Deputy does not use this framework or vulnerable components, and its systems have not been impacted by the events. While we are not impacted, our teams are monitoring the situation.

Built onSafeBase by Drata Logo