Hush Security’s Trust Center Ask a question

Hush Security – Enterprise Security for Enterprise AI Agents

Security overview

Hush is purpose-built for the non-human workforce: it continuously monitors every agent, secret and workload at runtime, prioritizes what is actively exploitable, and systematically eliminates risk by shifting from secrets to identity-based access. Hush gives every AI agent and non-human identity its own verifiable identity and delegated permissions: every action centrally governed, scoped to the task, and revoked when done.

Because organizations trust us to sit at the heart of how their agents, workloads and services access sensitive systems, we hold ourselves to the same standard of least privilege, zero standing access and full auditability that we deliver to our customers. Our platform runs on AWS, is built and operated under a formal Secure Software Development Lifecycle, and is independently audited. Our SOC 2 Type II examination by Deloitte covered Security, Availability and Confidentiality for 1 May 2025 to 30 April 2026 with no exceptions noted, and we are certified to ISO/IEC 27001 and ISO/IEC 42001. We also practise what we build: Hush uses its own secretless platform internally, practically eliminating long-lived secrets across the organization.

If you have questions that go beyond what is documented here, our security team is available at security@hush.security.

Compliance

SOC 2 Type II — Security, Availability, Confidentiality

SOC 2 Type II — Security, Availability, Confidentiality

Compliant

Monitored by CISO99 continuous compliance scans.

ISO/IEC 27001:2022

ISO/IEC 27001:2022

Compliant

Monitored by CISO99 continuous compliance scans.

ISO/IEC 42001 — AI Management System

ISO/IEC 42001 — AI Management System

Compliant

Monitored by CISO99 continuous compliance scans.

EU AI Act — assessed, not high-risk

EU AI Act — assessed, not high-risk

Compliant

Monitored by CISO99 continuous compliance scans.

GDPR

GDPR

Compliant

Monitored by CISO99 continuous compliance scans.

CCPA

CCPA

Compliant

Monitored by CISO99 continuous compliance scans.

IPA (Israel Privacy Protection Law)

IPA (Israel Privacy Protection Law)

Compliant

Monitored by CISO99 continuous compliance scans.

Controls

Updated Oct 7, 2026 View all

Application Security

  • Secure Software Development Lifecycle established
  • Change management procedures enforced
  • Mandatory peer code review
View 6 more Application Security controls

Access Control

  • Role Based Access Control (RBAC) established
  • Multi-factor authentication enforced
  • Quarterly user access reviews
View 5 more Access Control controls

Encryption

  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • Mutual TLS between internal services
View 2 more Encryption controls

Data Security

  • Secret values are never stored
  • Strict tenant isolation
  • No production data in non-production environments
View 2 more Data Security controls

Network Security

  • Network segmentation into security zones
  • Databases in private subnets
  • Least-privilege network access rules
View 4 more Network Security controls

Infrastructure

  • Hosted on AWS across multiple Availability Zones
  • Infrastructure as Code
  • Hardening aligned to CIS benchmarks
View 3 more Infrastructure controls

Endpoint Security

  • Endpoint Detection and Response deployed
  • Mobile Device Management enforced
  • Full-disk encryption enforced
View 4 more Endpoint Security controls

Corporate Security

  • Information Security Policy reviewed annually
  • Annual risk assessment and treatment
  • Asset management maintained
View 5 more Corporate Security controls

Incident Response

  • Incident Response Policy and program established
  • Customer notification within 24 hours
  • 24/7 security alerting to on-call
View 2 more Incident Response controls

Business Continuity

  • Business Continuity and Disaster Recovery plans established
  • Disaster recovery tested annually
  • Automated encrypted backups
View 1 more Business Continuity control

Availability

  • 99.5% availability SLA
  • Recovery Time Objective of 12 hours
  • Recovery Point Objective of up to 24 hours
View 1 more Availability control

Privacy

  • Data Protection Officer function established
  • Compliance with GDPR, CCPA and the Israel Privacy Protection Law
  • Data subject rights supported
View 2 more Privacy controls

Vendor Management

  • Vendor risk assessment before onboarding
  • Ongoing monitoring of subservice organizations
  • Contractual security and confidentiality terms with third parties

Product Security

Updated Oct 7, 2026 View all

Secure Development

  • Threat modelling and design review for every new feature
  • Security analysis and senior review on every pull request
  • SAST, DAST, SCA, secrets and container scanning on every change
View 2 more Secure Development items

Product Authentication & Access

  • SAML 2.0 single sign-on supported
  • SCIM and SAML-based provisioning and de-provisioning supported
  • Two-factor authentication for administrators
View 2 more Product Authentication & Access items

AI Security & Guardrails

  • AI models accessed exclusively through Amazon Bedrock with guardrails on prompts and outputs
  • Zero data retention and zero training at the model provider
  • No customer data used for model training or fine-tuning
View 2 more AI Security & Guardrails items

Tenant Isolation & Data Protection

  • Strict multi-tenant isolation, validated by annual penetration testing
  • Secret values never stored — metadata only
  • Encryption in transit and at rest (TLS 1.3 / mTLS, AES-256 under AWS KMS)
View 2 more Tenant Isolation & Data Protection items

Infrastructure & Deployment Security

  • AWS us-east-1 across multiple Availability Zones
  • Infrastructure as Code (Terraform) on Kubernetes with automated rollback
  • Segmented network with databases in private subnets
View 3 more Infrastructure & Deployment Security items

Auditability

  • End-to-end audit logs across application, API, infrastructure, database, network and access layers
  • Logs centralised in Coralogix, outside production, with immutability controls
  • Every agent and identity action attributed to an accountable owner
View 1 more Auditability item

Resources

View all

Certifications & audits

View 1 more Certifications & audits resource

Penetration tests

Policies

Privacy

Other documents

Subprocessors

View all

Frequently asked questions

How is my data encrypted?

All data in transit is encrypted with TLS 1.3 externally (TLS 1.2 minimum, Perfect Forward Secrecy, HSTS) and mutual TLS between internal services. Data at rest, including backups, is encrypted with AES-256 under AWS KMS keys that are rotated annually, audit-logged and never exposed in plaintext.

Which compliance certifications does Hush hold?

Hush holds a SOC 2 Type II report covering Security, Availability and Confidentiality, audited by Deloitte for 1 May 2025 to 30 April 2026 with no exceptions noted. Hush is also certified to ISO/IEC 27001:2022 and ISO/IEC 42001, and complies with GDPR, CCPA and the Israel Privacy Protection Law.

How does Hush handle privacy and data subject requests?

Hush's privacy program is overseen by the Hush Legal team, acting as Data Protection Officer, and complies with GDPR, CCPA and the Israel Privacy Protection Law. Hush collects only the metadata needed to operate the platform, never stores secret values, and supports data subject rights including access, deletion and the right to object to automated decision-making. Privacy questions can be sent to security@hush.security.

Does Hush store my secrets?

No. Hush collects metadata about secrets and non-human identities, such as type, location, name, exposure context and usage behaviour, to evaluate them against hygiene rules. Actual secret values are never stored.

Who can access customer data?

Access follows least privilege and need-to-know, enforced through role-based access control and Okta SSO with non-bypassable MFA. Employee devices never connect directly to production; administrative access is brokered through AWS Systems Manager Session Manager with MFA, an approval workflow, time-bounded permissions and full session recording. Access is reviewed quarterly.

Does Hush perform penetration testing and vulnerability scanning?

Yes. An independent application penetration test is conducted annually following OWASP WSTG and PTES, alongside quarterly external vulnerability scans and automated SAST, DAST, SCA, secrets and container scanning on every code change. Critical vulnerabilities are patched within 24 hours, High within 7 days and Medium within 30 days. A penetration test letter is available on request.

How does Hush use AI, and is my data used to train models?

Hush's AI features run through Amazon Bedrock with guardrails, zero data retention and zero training. Neither Hush nor its model providers train or fine-tune models on customer data. AI outputs are advisory only: they never trigger automations, grant access or change configurations, and are subject to human review.

What happens if there is a service disruption or security incident?

Hush maintains a documented Incident Response Program and tested Business Continuity and Disaster Recovery plans. Customers are notified within 24 hours of any incident that impacts, or is reasonably suspected to impact, their data, security or service availability, followed by ongoing updates and a post-incident report. Production runs across multiple AWS Availability Zones with a 12-hour RTO, an RPO of up to 24 hours and a 99.5% availability SLA.

Where is my data stored, and is it isolated from other customers?

Customer data is stored in AWS us-east-1 (N. Virginia) across multiple Availability Zones, with encrypted daily backups replicated across zones and regions. Strict tenant isolation is enforced through tenant-specific identifiers and access controls and validated through penetration testing.

How does Hush handle data retention and deletion?

Hush maintains a formal Data Retention Policy, reviewed annually. Customer data is retained for the duration of the contract plus 30 days and then securely deleted, with early deletion available on request at any time.

How are logs collected and protected?

Audit logs span the application, API, infrastructure, database, network and production access layers and are shipped to Coralogix, outside the production environment, together with AWS CloudTrail, CloudWatch and GuardDuty. Logs are protected by encryption, access controls and immutability so they cannot be altered by the administrators they describe, and can be made available to customers on request.

Which authentication options does the Hush platform support?

The Hush console supports SAML 2.0 single sign-on, SCIM and SAML-based provisioning and de-provisioning, two-factor authentication for administrators, and role-based access control. Customers can configure security settings and view access logs and security events from a self-service console.

Does Hush use third-party subprocessors?

Yes. Hush uses a limited set of vetted subprocessors, listed on this page. Every vendor goes through a risk assessment before onboarding and is monitored on an ongoing basis. The complete sub-processor list is available on request.

How do I report a security issue?

Please email security@hush.security. Reports are tracked and reviewed by our security team.