- Can Deputy AI act on its own without my initiation or approval?
- Does Deputy AI respect my existing user permissions?
- What employee data does Deputy AI access to perform its tasks?
- What happens if Deputy AI makes a mistake?
- How does Deputy segregate customer data from other clients?
Trust Center Updates
Keyv npm Supply-Chain Compromise
On August 4, 2026, several npm packages in the keyv/cacheable ecosystem were compromised, resulting in the publication of malicious package versions.
Deputy has assessed its dependencies and build systems and confirmed that no affected package versions were introduced into our environment. Our systems and customer data have not been impacted by the events.
As this campaign is still developing, we are continuing to monitor published indicators and will update this notice if our assessment changes.
New SOC2 Type 2 report available
We are pleased to announce the successful completion of our latest SOC 2 assessment and the receipt of our official attestation report. You may now request a copy of the new report directly through this Trust Center.
Deputy not impacted by React Framework
Deputy is aware of the recently announced critical vulnerability affecting the React framework and React Server Components (RSC). Deputy does not use this framework or vulnerable components, and its systems have not been impacted by the events. While we are not impacted, our teams are monitoring the situation.




