What we do
- AI agent consulting: we pick the processes where an agent pays off, and say so when it does not.
- AI agent development: role, skills, channels, permissions and escalation rules, built with your team.
- Secure deployment in your cloud account or on your servers, so you decide where your data lives.
- Integration with your CRM, ERP, document repositories, email and chat channels through allow-listed connectors.
- Operation after go-live: monitoring, controlled updates, cost limits and indicator reporting.
How remote delivery works
We do not have an office in the United States or Canada. Our team works remotely from Medellín and Taipei.
Colombia is on UTC-5 all year and does not observe daylight saving time. That matches US Eastern time in winter and US Central time in summer, so our working day overlaps substantially with North American business hours. Our Taipei office adds a second time zone to the team.
Agents our clients run today
Real deployments on AgenticOS, anonymized. The same platform and controls apply to companies in North America.
| Client | Agents in production |
|---|---|
| A Latin American marketing agency | A team of agents that coordinates internal work, serves clients, manages online stores and runs paid media campaigns. |
| A Mexican university | Agents that support financial management, serve the university community, act as chief of staff and run marketing. |
| A logistics company | An agent that gathers information scattered across sources, validates it and makes it available to the team in a conversation. |
| A circular-economy company | A chief-of-staff agent that handles coordination: tracking commitments, reminders and the status of each workstream. |
Appropia itself runs agents for PMO, marketing, chief of staff, software development and finance and accounting. Several clients operate dozens of agents in production.
Regulatory context in the United States
There is no general federal AI law in the United States. The reference most companies use for AI governance is the NIST AI Risk Management Framework (AI RMF 1.0), published in January 2023. It is voluntary and organizes AI risk work into four functions: Govern, Map, Measure and Manage. In July 2024 NIST added the Generative AI Profile (NIST AI 600-1), which applies the framework to generative AI risks.
For personal data, there is no general federal privacy law; state laws such as California's CCPA, as amended by the CPRA, and sector-specific rules apply.
Regulatory context in Canada
Canada has no federal AI statute in force. The proposed Artificial Intelligence and Data Act (AIDA), part of Bill C-27, died on the Order Paper when Parliament was prorogued in January 2025.
PIPEDA remains the federal privacy law for the private sector. In Quebec, Law 25 amended the private-sector privacy act and requires organizations to inform people when a decision about them is based exclusively on automated processing of their personal information.
This is context, not legal advice. Your counsel should confirm which rules apply to each use case.
How our security framework maps to NIST AI RMF
A high-level reading, not a certification or a formal crosswalk. The controls come from our public AgenticOS Security Framework.
| NIST AI RMF function | AgenticOS Security Framework controls |
|---|---|
| Govern | A named human owner per agent, a list of actions that require approval, periodic permission reviews and a rehearsed incident response plan. |
| Map | Classification of the data each agent uses, rules on which model may process which data, and an inventory of skills, connectors and versions. |
| Measure | Prompt-injection and permission-abuse tests before production, quality evaluation with real cases, and indicators per agent. |
| Manage | Least privilege, isolated runtimes, pinned and reviewed skills, cost and rate limits, a tamper-proof audit log and a tested shutdown procedure. |
For PIPEDA and Quebec's Law 25, the same controls help in practice: the audit log records what data an agent used and why, data rules limit what leaves your environment, and human approval keeps people in decisions that affect individuals.
How an engagement works
- Assessment: processes, data, systems and risk. We agree on the first use case and its metric.
- Pilot of about 30 days: one agent, limited data, an isolated environment and human approval on everything.
- Production: per-agent identity and permissions, full audit trail and monitoring.
- Operate and scale: more agents and areas, with periodic reviews.
Why Appropia
- We run agents in production, for clients and for our own company, not just demos.
- A public security framework you can review before you hire us.
- More than a decade of enterprise document repositories and processes since 2013, the foundation agents depend on.
- Official member of Anthropic's Claude Partner Network (Registered tier) and of the NVIDIA Connect Program.
Frequently asked questions
Do you have an office in the United States or Canada?+
No. We deliver remotely from Medellín, Colombia, and Taipei, Taiwan. Colombia is on UTC-5 all year, which overlaps substantially with North American business hours.
Where is our data stored?+
In your infrastructure: we deploy in your cloud account or on your servers, so you decide where your data lives.
Is there an AI law we must comply with?+
There is no general federal AI statute in force in the United States or Canada. The NIST AI RMF is a voluntary reference, and privacy laws such as state laws in the US, PIPEDA and Quebec's Law 25 still apply. This is not legal advice.
What does an AI agent development company like Appropia deliver?+
Agents working in your process: design, deployment, integration and operation, with permissions, human approval and an audit trail.
Do you have clients in the US or Canada?+
We serve companies in the United States and Canada remotely, with the same platform, framework and process we use with our clients in Latin America.
Keep reading