Security overview
Hush is purpose-built for the non-human workforce: it continuously monitors every agent, secret and workload at runtime, prioritizes what is actively exploitable, and systematically eliminates risk by shifting from secrets to identity-based access. Hush gives every AI agent and non-human identity its own verifiable identity and delegated permissions: every action centrally governed, scoped to the task, and revoked when done.
Because organizations trust us to sit at the heart of how their agents, workloads and services access sensitive systems, we hold ourselves to the same standard of least privilege, zero standing access and full auditability that we deliver to our customers. Our platform runs on AWS, is built and operated under a formal Secure Software Development Lifecycle, and is independently audited. Our SOC 2 Type II examination by Deloitte covered Security, Availability and Confidentiality for 1 May 2025 to 30 April 2026 with no exceptions noted, and we are certified to ISO/IEC 27001 and ISO/IEC 42001. We also practise what we build: Hush uses its own secretless platform internally, practically eliminating long-lived secrets across the organization.
If you have questions that go beyond what is documented here, our security team is available at security@hush.security.
Compliance
SOC 2 Type II — Security, Availability, Confidentiality
SOC 2 Type II — Security, Availability, Confidentiality
Compliant
Monitored by CISO99 continuous compliance scans.
ISO/IEC 27001:2022
ISO/IEC 27001:2022
Compliant
Monitored by CISO99 continuous compliance scans.
ISO/IEC 42001 — AI Management System
ISO/IEC 42001 — AI Management System
Compliant
Monitored by CISO99 continuous compliance scans.
EU AI Act — assessed, not high-risk
EU AI Act — assessed, not high-risk
Compliant
Monitored by CISO99 continuous compliance scans.
GDPR
GDPR
Compliant
Monitored by CISO99 continuous compliance scans.
CCPA
CCPA
Compliant
Monitored by CISO99 continuous compliance scans.
IPA (Israel Privacy Protection Law)
IPA (Israel Privacy Protection Law)
Compliant
Monitored by CISO99 continuous compliance scans.
Application Security
- Secure Software Development Lifecycle established
- Change management procedures enforced
- Mandatory peer code review
Access Control
- Role Based Access Control (RBAC) established
- Multi-factor authentication enforced
- Quarterly user access reviews
Encryption
- AES-256 encryption at rest
- TLS 1.3 in transit
- Mutual TLS between internal services
Data Security
- Secret values are never stored
- Strict tenant isolation
- No production data in non-production environments
Network Security
- Network segmentation into security zones
- Databases in private subnets
- Least-privilege network access rules
Infrastructure
- Hosted on AWS across multiple Availability Zones
- Infrastructure as Code
- Hardening aligned to CIS benchmarks
Endpoint Security
- Endpoint Detection and Response deployed
- Mobile Device Management enforced
- Full-disk encryption enforced
Corporate Security
- Information Security Policy reviewed annually
- Annual risk assessment and treatment
- Asset management maintained
Incident Response
- Incident Response Policy and program established
- Customer notification within 24 hours
- 24/7 security alerting to on-call
Business Continuity
- Business Continuity and Disaster Recovery plans established
- Disaster recovery tested annually
- Automated encrypted backups
Availability
- 99.5% availability SLA
- Recovery Time Objective of 12 hours
- Recovery Point Objective of up to 24 hours
Privacy
- Data Protection Officer function established
- Compliance with GDPR, CCPA and the Israel Privacy Protection Law
- Data subject rights supported
Vendor Management
- Vendor risk assessment before onboarding
- Ongoing monitoring of subservice organizations
- Contractual security and confidentiality terms with third parties
Secure Development
- Threat modelling and design review for every new feature
- Security analysis and senior review on every pull request
- SAST, DAST, SCA, secrets and container scanning on every change
Product Authentication & Access
- SAML 2.0 single sign-on supported
- SCIM and SAML-based provisioning and de-provisioning supported
- Two-factor authentication for administrators
AI Security & Guardrails
- AI models accessed exclusively through Amazon Bedrock with guardrails on prompts and outputs
- Zero data retention and zero training at the model provider
- No customer data used for model training or fine-tuning
Tenant Isolation & Data Protection
- Strict multi-tenant isolation, validated by annual penetration testing
- Secret values never stored — metadata only
- Encryption in transit and at rest (TLS 1.3 / mTLS, AES-256 under AWS KMS)
Infrastructure & Deployment Security
- AWS us-east-1 across multiple Availability Zones
- Infrastructure as Code (Terraform) on Kubernetes with automated rollback
- Segmented network with databases in private subnets
Auditability
- End-to-end audit logs across application, API, infrastructure, database, network and access layers
- Logs centralised in Coralogix, outside production, with immutability controls
- Every agent and identity action attributed to an accountable owner
Resources
View allCertifications & audits
- SOC 2 Type II report (May 2025 – April 2026) Request access
- ISO 27001 certificate Request access
- ISO 27001 audit report Request access
- ISO 27001 Statement of Applicability Request access
Penetration tests
- Penetration test confirmation letter (2026) Request access
Policies
- Information security policy Request access
- Encryption control policy Request access
- Vulnerability management policy Request access
Privacy
Other documents
- Network architecture overview Request access
- Cyber liability insurance certificate Request access
- Hush Security documentation
Subprocessors
View all- Amazon Web Services (AWS) • Cloud hosting and infrastructure US
- Amazon Bedrock • AI / LLM services (zero data retention, no training) US
- Coralogix • Logging & monitoring US
- PostHog • Product analytics
Frequently asked questions
How is my data encrypted?
All data in transit is encrypted with TLS 1.3 externally (TLS 1.2 minimum, Perfect Forward Secrecy, HSTS) and mutual TLS between internal services. Data at rest, including backups, is encrypted with AES-256 under AWS KMS keys that are rotated annually, audit-logged and never exposed in plaintext.
Which compliance certifications does Hush hold?
Hush holds a SOC 2 Type II report covering Security, Availability and Confidentiality, audited by Deloitte for 1 May 2025 to 30 April 2026 with no exceptions noted. Hush is also certified to ISO/IEC 27001:2022 and ISO/IEC 42001, and complies with GDPR, CCPA and the Israel Privacy Protection Law.
How does Hush handle privacy and data subject requests?
Hush's privacy program is overseen by the Hush Legal team, acting as Data Protection Officer, and complies with GDPR, CCPA and the Israel Privacy Protection Law. Hush collects only the metadata needed to operate the platform, never stores secret values, and supports data subject rights including access, deletion and the right to object to automated decision-making. Privacy questions can be sent to security@hush.security.
Does Hush store my secrets?
No. Hush collects metadata about secrets and non-human identities, such as type, location, name, exposure context and usage behaviour, to evaluate them against hygiene rules. Actual secret values are never stored.
Who can access customer data?
Access follows least privilege and need-to-know, enforced through role-based access control and Okta SSO with non-bypassable MFA. Employee devices never connect directly to production; administrative access is brokered through AWS Systems Manager Session Manager with MFA, an approval workflow, time-bounded permissions and full session recording. Access is reviewed quarterly.
Does Hush perform penetration testing and vulnerability scanning?
Yes. An independent application penetration test is conducted annually following OWASP WSTG and PTES, alongside quarterly external vulnerability scans and automated SAST, DAST, SCA, secrets and container scanning on every code change. Critical vulnerabilities are patched within 24 hours, High within 7 days and Medium within 30 days. A penetration test letter is available on request.
How does Hush use AI, and is my data used to train models?
Hush's AI features run through Amazon Bedrock with guardrails, zero data retention and zero training. Neither Hush nor its model providers train or fine-tune models on customer data. AI outputs are advisory only: they never trigger automations, grant access or change configurations, and are subject to human review.
What happens if there is a service disruption or security incident?
Hush maintains a documented Incident Response Program and tested Business Continuity and Disaster Recovery plans. Customers are notified within 24 hours of any incident that impacts, or is reasonably suspected to impact, their data, security or service availability, followed by ongoing updates and a post-incident report. Production runs across multiple AWS Availability Zones with a 12-hour RTO, an RPO of up to 24 hours and a 99.5% availability SLA.
Where is my data stored, and is it isolated from other customers?
Customer data is stored in AWS us-east-1 (N. Virginia) across multiple Availability Zones, with encrypted daily backups replicated across zones and regions. Strict tenant isolation is enforced through tenant-specific identifiers and access controls and validated through penetration testing.
How does Hush handle data retention and deletion?
Hush maintains a formal Data Retention Policy, reviewed annually. Customer data is retained for the duration of the contract plus 30 days and then securely deleted, with early deletion available on request at any time.
How are logs collected and protected?
Audit logs span the application, API, infrastructure, database, network and production access layers and are shipped to Coralogix, outside the production environment, together with AWS CloudTrail, CloudWatch and GuardDuty. Logs are protected by encryption, access controls and immutability so they cannot be altered by the administrators they describe, and can be made available to customers on request.
Which authentication options does the Hush platform support?
The Hush console supports SAML 2.0 single sign-on, SCIM and SAML-based provisioning and de-provisioning, two-factor authentication for administrators, and role-based access control. Customers can configure security settings and view access logs and security events from a self-service console.
Does Hush use third-party subprocessors?
Yes. Hush uses a limited set of vetted subprocessors, listed on this page. Every vendor goes through a risk assessment before onboarding and is monitored on an ongoing basis. The complete sub-processor list is available on request.
How do I report a security issue?
Please email security@hush.security. Reports are tracked and reviewed by our security team.