Audited, certified, and honest about what is still in progress
Security, availability and confidentiality controls audited over a period, not at a point in time. Report available on request.
Certified information security management system covering people, process and technology.
Lawful basis, data subject rights, a data processing agreement and standard contractual clauses for EU customers.
India’s Digital Personal Data Protection Act: consent, purpose limitation and grievance handling for Indian data principals.
Independent VAPT of the platform every year, findings remediated, summary available on request.
The AI management system standard: how we build, evaluate and govern the agents.
Administrative, technical and physical safeguards for customers who handle health data.
Tell us which questionnaire you are filling in and we answer it line by line, with evidence attached.
Talk to usFour commitments that do not change by plan
Your data is yours
Customer data is processed for your own insights. It is never shared, sold or used to train models for anyone else.
Encrypted in transit and at rest
Every connection uses TLS. Data stores and backups are encrypted at rest with keys managed by us, not the vendor.
Deleted when you say so
Disconnect a source or close a workspace and the data is deleted and confirmed. Backups age out on a fixed schedule.
Least privilege inside HyperOrbit
Production access is limited to named engineers, behind SSO and MFA, logged and reviewed.
Controls, by domain
- SSO and MFA for workspace users
- Role-based access per workspace
- Audit log of user and agent actions
- Agents act only within the autonomy level you set
- Encryption at rest and in transit
- Production database access restricted and logged
- Customer data segregated per workspace
- Deletion on request, with confirmation
- Peer-reviewed changes with approval before release
- Dependency and vulnerability scanning
- Annual independent penetration test
- Secrets managed outside the codebase
- Private networking for production systems
- Firewall rules on a least-access basis
- External connections monitored
- DDoS protection at the edge
- Managed devices with full-disk encryption
- Anti-malware and automatic patching
- Screen lock and remote wipe
- No customer data on personal devices
- Background checks on hire
- Security training at onboarding and every year
- Incident response plan, tested
- Vendor risk review before any new sub-processor
Summarised from our SOC 2 and ISO 27001 control set. The full list, with evidence, is in the reports below.
Reports and policies, on request
Reports go out under NDA. Policies go out on request. A person sends them within one working day; nothing here is gated behind a sales call.
- SOC 2 Type II reportUnder NDA
- ISO 27001:2022 certificateUnder NDA
- Penetration test summaryUnder NDA
- Data processing agreement (DPA)Under NDA
- Information security policyPolicy
- Data protection and privacy policyPolicy
- Access control policyPolicy
- Incident management policyPolicy
- Business continuity and disaster recovery policyPolicy
- Vendor management policyPolicy
- Acceptable use policyPolicy
- Secure development policyPolicy
- Data retention and deletion policyPolicy
- Privacy policyPublicRead it
Who else touches the data
| Vendor | Purpose |
|---|---|
| Amazon Web Services | Cloud hosting, content delivery network, AI-enabled functionality |
| Anthropic | AI-enabled functionality |
| PostHog | Backend infrastructure services |
| Email and office applications, AI-enabled functionality | |
| OpenAI | AI-enabled functionality |
| Resend | Email service provider |
| Zapier | Customer support |
| OpenRouter | Backend infrastructure services |
| HubSpot | CRM |
| Cloudflare | Web application firewall |
| Slack | Internal communications |
| Atlassian | Wiki and change management |
| Cal.com | Calendar scheduling |
| Stripe | Payment processing |
Last updated September 2026. Customers are told before a vendor is added. Hosting regions are set out in the data processing agreement.
Found something? Tell us first.
Email agent@hyperorbit.ai with the subject “Security disclosure” and enough detail to reproduce it. We acknowledge every report, keep you informed until it is resolved, and do not pursue researchers acting in good faith.
Before your security review
Do you train models on our data?
No. Your data is processed to produce your own insights and nothing else. It is never used to train models for other customers or for anyone outside HyperOrbit.
Can we sign a data processing agreement?
Yes. Request the DPA from this page and we send it for signature. It includes standard contractual clauses for EU customers and the commitments DPDPA requires for Indian data principals.
Can we see the SOC 2 report?
Yes, under NDA. Request it here and a person emails it within one working day, together with the ISO 27001 certificate and the latest penetration test summary if you ask for them.
Where is our data hosted?
On Amazon Web Services. The regions used for your workspace are set out in the data processing agreement, and every vendor that touches data is named in the sub-processor list on this page.
How do we delete our data?
Disconnect a source to stop the read and remove its data, or ask us to close the workspace. Deletion is completed and confirmed in writing; backups age out on a fixed schedule.
Do you support SSO?
Yes. Workspace users can sign in with SSO, and MFA is enforced. Role-based access controls what each person and each agent can see and do.
How do I report a security issue?
Use the Report a vulnerability button on this page, or email agent@hyperorbit.ai with the subject “Security disclosure”. We acknowledge every report, keep you informed until it is resolved, and do not pursue researchers acting in good faith.
Bring your security questionnaire
We answer it line by line, with the evidence attached. Most reviews close in a week.