[ RESOURCES | TRUST & COMPLIANCE ]

Your customers’ data, handled like it is ours.

HyperOrbit is SOC 2 Type II audited, ISO 27001:2022 certified and compliant with GDPR and India’s DPDPA, with an independent penetration test every year. HyperOrbit reads your customers’ calls, tickets and reviews, so the controls around that data matter as much as the read itself. This page lists what we certify, how data is handled, the documents you can request and how to reach us about security.

SOC 2 TYPE II · ISO 27001:2022 · GDPR · DPDPA · PENTESTED ANNUALLY
[ 01 | WHERE WE STAND ]

Audited, certified, and honest about what is still in progress

SOC 2 Type IICompliant

Security, availability and confidentiality controls audited over a period, not at a point in time. Report available on request.

ISO 27001:2022Certified

Certified information security management system covering people, process and technology.

GDPRCompliant

Lawful basis, data subject rights, a data processing agreement and standard contractual clauses for EU customers.

DPDPACompliant

India’s Digital Personal Data Protection Act: consent, purpose limitation and grievance handling for Indian data principals.

Penetration testingAnnual

Independent VAPT of the platform every year, findings remediated, summary available on request.

ISO 42001In progress

The AI management system standard: how we build, evaluate and govern the agents.

HIPAAIn progress

Administrative, technical and physical safeguards for customers who handle health data.

Need another framework?

Tell us which questionnaire you are filling in and we answer it line by line, with evidence attached.

Talk to us
[ 02 | HOW WE HANDLE DATA ]

Four commitments that do not change by plan

YOURS

Your data is yours

Customer data is processed for your own insights. It is never shared, sold or used to train models for anyone else.

ENCRYPTED

Encrypted in transit and at rest

Every connection uses TLS. Data stores and backups are encrypted at rest with keys managed by us, not the vendor.

DELETED

Deleted when you say so

Disconnect a source or close a workspace and the data is deleted and confirmed. Backups age out on a fixed schedule.

LEAST PRIVILEGE

Least privilege inside HyperOrbit

Production access is limited to named engineers, behind SSO and MFA, logged and reviewed.

[ 03 | WHAT THE AUDITS COVER ]

Controls, by domain

Product security
  • SSO and MFA for workspace users
  • Role-based access per workspace
  • Audit log of user and agent actions
  • Agents act only within the autonomy level you set
Data security
  • Encryption at rest and in transit
  • Production database access restricted and logged
  • Customer data segregated per workspace
  • Deletion on request, with confirmation
Application security
  • Peer-reviewed changes with approval before release
  • Dependency and vulnerability scanning
  • Annual independent penetration test
  • Secrets managed outside the codebase
Network security
  • Private networking for production systems
  • Firewall rules on a least-access basis
  • External connections monitored
  • DDoS protection at the edge
Endpoint security
  • Managed devices with full-disk encryption
  • Anti-malware and automatic patching
  • Screen lock and remote wipe
  • No customer data on personal devices
Corporate security
  • Background checks on hire
  • Security training at onboarding and every year
  • Incident response plan, tested
  • Vendor risk review before any new sub-processor

Summarised from our SOC 2 and ISO 27001 control set. The full list, with evidence, is in the reports below.

[ 04 | DOCUMENTS ]

Reports and policies, on request

Reports go out under NDA. Policies go out on request. A person sends them within one working day; nothing here is gated behind a sales call.

REPORTS AND AGREEMENTS
  • SOC 2 Type II reportUnder NDA
  • ISO 27001:2022 certificateUnder NDA
  • Penetration test summaryUnder NDA
  • Data processing agreement (DPA)Under NDA
POLICIES
  • Information security policyPolicy
  • Data protection and privacy policyPolicy
  • Access control policyPolicy
  • Incident management policyPolicy
  • Business continuity and disaster recovery policyPolicy
  • Vendor management policyPolicy
  • Acceptable use policyPolicy
  • Secure development policyPolicy
  • Data retention and deletion policyPolicy
  • Privacy policyPublicRead it
[ 05 | SUB-PROCESSORS ]

Who else touches the data

VendorPurpose
Amazon Web ServicesCloud hosting, content delivery network, AI-enabled functionality
AnthropicAI-enabled functionality
PostHogBackend infrastructure services
GoogleEmail and office applications, AI-enabled functionality
OpenAIAI-enabled functionality
ResendEmail service provider
ZapierCustomer support
OpenRouterBackend infrastructure services
HubSpotCRM
CloudflareWeb application firewall
SlackInternal communications
AtlassianWiki and change management
Cal.comCalendar scheduling
StripePayment processing

Last updated September 2026. Customers are told before a vendor is added. Hosting regions are set out in the data processing agreement.

[ 06 | RESPONSIBLE DISCLOSURE ]

Found something? Tell us first.

Email agent@hyperorbit.ai with the subject “Security disclosure” and enough detail to reproduce it. We acknowledge every report, keep you informed until it is resolved, and do not pursue researchers acting in good faith.

Report a vulnerability
[ 07 | FAQ ]

Before your security review

Do you train models on our data?

No. Your data is processed to produce your own insights and nothing else. It is never used to train models for other customers or for anyone outside HyperOrbit.

Can we sign a data processing agreement?

Yes. Request the DPA from this page and we send it for signature. It includes standard contractual clauses for EU customers and the commitments DPDPA requires for Indian data principals.

Can we see the SOC 2 report?

Yes, under NDA. Request it here and a person emails it within one working day, together with the ISO 27001 certificate and the latest penetration test summary if you ask for them.

Where is our data hosted?

On Amazon Web Services. The regions used for your workspace are set out in the data processing agreement, and every vendor that touches data is named in the sub-processor list on this page.

How do we delete our data?

Disconnect a source to stop the read and remove its data, or ask us to close the workspace. Deletion is completed and confirmed in writing; backups age out on a fixed schedule.

Do you support SSO?

Yes. Workspace users can sign in with SSO, and MFA is enforced. Role-based access controls what each person and each agent can see and do.

How do I report a security issue?

Use the Report a vulnerability button on this page, or email agent@hyperorbit.ai with the subject “Security disclosure”. We acknowledge every report, keep you informed until it is resolved, and do not pursue researchers acting in good faith.

Bring your security questionnaire

We answer it line by line, with the evidence attached. Most reviews close in a week.