Skip to content

Legal

Security

Updated

Security is a design constraint at Hyperpriors, not a feature tier. This page describes our current posture during the private beta — what we do today, what we will not claim, and how to reach us if something looks wrong.

Data handling

Traces and evaluation records are encrypted at rest and in transit. Customers control retention windows on the Production and Regulated tiers. Deletion requests are honoured across primary storage and backups within a documented interval.

Customer data is never used to train models — ours or anyone else’s.

Access control

Production access is limited to named engineers, protected by hardware-key multi-factor authentication, and logged. Administrative actions are attributable. We do not share credentials between people, and we do not use shared accounts.

Isolation

Customer projects are isolated at the data layer. Design partners on the Regulated path can name a residency region; self-hosted trace storage is available under agreement.

Subprocessors

We use a small set of established infrastructure providers for hosting, storage, and email. A current list is available on request at ai@hyperpriors.com. Each processes data only on our instructions.

Vulnerability disclosure

If you believe you have found a vulnerability, write to ai@hyperpriors.com with enough detail to reproduce it. We acknowledge reports within two working days and keep reporters informed through to resolution. We prefer coordinated disclosure; we do not offer a public bounty during private beta.

What we will not claim yet

Formal certification work — including SOC 2 Type II — is planned as the platform moves from private beta to general availability. Until then, we will not put a logo wall of accreditations on this page. We will walk through our controls in detail with design partners who need them.

Contact

Security questions, vendor questionnaires, and disclosure reports: ai@hyperpriors.com.