Hobasa
Security

Enterprise-grade security by default.

We are reviewing the detailed description of our security program and AI governance controls before publishing them here. In the meantime, the following applies:

ISO 27001 - Certified

Information security management system certified to the international standard.

SOC 2 Type II

In active audit - Report expected in Q3. Not certified. Controls are under independent review for security and availability.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest, customer-isolated keys.

PII masked by default

Sensitive fields tokenized before any model ever sees them.

Never used to train external models

Your data is never used to train any external model. Where a model provider processes data in order to return your result, it does so under contract, on scrubbed and minimized inputs.

24x7 monitoring

Continuous observability with on-call response.

For security questions, due-diligence requests or a copy of our current documentation, please contact us at security@hobasa.com.