Legal
Security
Updated
Security is a design constraint at Hyperpriors, not a feature tier. This page describes our current posture during the private beta — what we do today, what we will not claim, and how to reach us if something looks wrong.
Data handling
Traces and evaluation records are encrypted at rest and in transit. Customers control retention windows on the Production and Regulated tiers. Deletion requests are honoured across primary storage and backups within a documented interval.
Customer data is never used to train models — ours or anyone else’s.
Access control
Production access is limited to named engineers, protected by hardware-key multi-factor authentication, and logged. Administrative actions are attributable. We do not share credentials between people, and we do not use shared accounts.
Isolation
Customer projects are isolated at the data layer. Design partners on the Regulated path can name a residency region; self-hosted trace storage is available under agreement.
Subprocessors
We use a small set of established infrastructure providers for hosting, storage, and email. A current list is available on request at ai@hyperpriors.com. Each processes data only on our instructions.
Vulnerability disclosure
If you believe you have found a vulnerability, write to ai@hyperpriors.com with enough detail to reproduce it. We acknowledge reports within two working days and keep reporters informed through to resolution. We prefer coordinated disclosure; we do not offer a public bounty during private beta.
What we will not claim yet
Formal certification work — including SOC 2 Type II — is planned as the platform moves from private beta to general availability. Until then, we will not put a logo wall of accreditations on this page. We will walk through our controls in detail with design partners who need them.
Contact
Security questions, vendor questionnaires, and disclosure reports: ai@hyperpriors.com.