Certifications and key safeguards
The controls we hold ourselves to, verified by independent auditors.
ISO 27001 Certified
Our information security management system is certified to the international ISO 27001 standard.
SOC 2 Type II Certified
Completed independent audit examining our operational controls in active practice, not just on paper.
Encryption everywhere
TLS 1.2+ with HSTS in transit, AES-256 at rest, and encrypted session tokens.
PII masked by default
Sensitive fields are tokenized before they reach any AI model.
Never used to train external models
Customer data is never used for AI model training. Not ours, not anyone else's.
Independent testing
Regular third-party penetration testing and vulnerability assessments, backed by tamper-evident audit logs.


Formal certificates and reports are available on request.
Secure ingestion at scale, without cutting corners on encryption or isolation.
Internal benchmark, ingestion only. Not a measure of end-to-end processing time.
Your data stays yours
Authoritative ownership
Your source systems keep the authoritative copy. No vendor lock-in.
Hyperscaler hosting
Deployed on major cloud hyperscalers across multiple availability zones.
Subprocessor due diligence
We maintain a vendor inventory with strict risk classification.
Common questions
Yes. Hobasa is SOC 2 Type II Certified and ISO 27001 Certified. Reports are available under NDA.
No. Your data is never used to train external models.
Hobasa reads only what is needed for analytics. Your source systems keep the authoritative copy.
No. Strict server-side tenant isolation keeps every client's data completely separate.
On major cloud hyperscalers, across multiple availability zones.
Yes. Contact security@hobasa.com for the complete security pack under NDA.