Hush Security’s Trust Center Ask a question

Hush Security – Enterprise Security for Enterprise AI Agents

Controls

Updated Oct 7, 2026

Application Security

  • Secure Software Development Lifecycle establishedFormal SSDLC with security requirements, threat modelling and design review for every new feature.
  • Change management procedures enforcedAll changes authorised, documented, tested in pre-production, reviewed and approved before production, with separation between authorising and implementing changes.
  • Mandatory peer code reviewEvery pull request is scanned for vulnerabilities and requires senior developer approval.
  • Static and dynamic application security testingSAST and DAST run automatically in CI/CD on every code change.
  • Software composition analysisThird-party and open-source dependencies scanned for vulnerabilities and licensing on every change.
  • Secrets and container image scanningSecrets scanning and container image scanning built into the CI/CD pipeline.
  • Critical and High vulnerabilities blocked from productionThe CI/CD pipeline prevents Critical and High findings from being released.
  • Annual third-party penetration testingIndependent application penetration test following OWASP WSTG and PTES methodologies.
  • Secure coding trainingOWASP Top 10 training for developers at onboarding and annually.

Access Control

  • Role Based Access Control (RBAC) establishedAccess granted on least-privilege and need-to-know principles.
  • Multi-factor authentication enforcedOkta SSO with non-bypassable MFA (push notification or passkey) across in-scope systems.
  • Quarterly user access reviewsUser permissions and privileged access are reviewed every quarter.
  • Privileged access approval workflowPrivileged access requires approval and is granted only through change management or just-in-time workflows.
  • Just-in-time, time-bounded production accessAdministrative access to production is brokered through AWS Systems Manager Session Manager with MFA and time-limited permissions.
  • Privileged sessions recordedPrivileged production sessions are recorded in full.
  • Privileged account sharing prohibited
  • Timely access revocation on offboarding

Encryption

  • AES-256 encryption at restApplied across DocumentDB, S3, EBS, Kubernetes secrets and backups.
  • TLS 1.3 in transitTLS 1.2 minimum, with Perfect Forward Secrecy and HSTS on all internet-facing hosts.
  • Mutual TLS between internal services
  • Encryption key management process establishedAWS KMS keys rotated annually, audit-logged and never exposed in plaintext.
  • Application secrets stored in AWS Secrets ManagerAccess to Secrets Manager is separately audited.

Data Security

  • Secret values are never storedHush stores only metadata about secrets and non-human identities: type, location, name and exposure context.
  • Strict tenant isolationEnforced through tenant-specific identifiers and access controls, validated by annual penetration testing.
  • No production data in non-production environmentsDevelopment, staging and production are fully separated across distinct VPCs and AWS accounts.
  • Data retention and secure deletion policyCustomer data is deleted within 30 days of contract termination, with early deletion available on request.
  • Data loss preventionSensitive data transmission over email is monitored and restricted; extracting customer data from production is prohibited by policy.

Network Security

  • Network segmentation into security zonesMulti-tier design separating public-facing components, application logic and data storage.
  • Databases in private subnetsDatabase services have no direct internet access.
  • Least-privilege network access rulesAWS Security Groups, NACLs and firewall rules allow only the required ports and protocols.
  • WAF and DDoS protectionAWS WAF with the OWASP Core Rule Set and rate limiting on all external services.
  • Continuous threat detectionAmazon GuardDuty with alerting on unauthorised access attempts.
  • Firewall rules monitored and reviewedOngoing monitoring by DevOps and an annual ruleset review.
  • Quarterly external vulnerability scans

Infrastructure

  • Hosted on AWS across multiple Availability ZonesProduction runs in us-east-1, built to the AWS Well-Architected Framework.
  • Infrastructure as CodeDeployed with Terraform onto Kubernetes through automated CI/CD with rollback capability.
  • Hardening aligned to CIS benchmarksDocumented Baseline Security Configuration Policy for operating systems, containers and applications.
  • Container base images rebuilt at least monthlyAutomated rebuilds are triggered when new vulnerabilities are detected.
  • Patch management SLAsCritical patches within 24 hours, High within 7 days, Medium within 30 days.
  • Centralised, tamper-resistant loggingAudit logs shipped to Coralogix outside the production estate, alongside CloudTrail and CloudWatch, protected by encryption, access controls and immutability.

Endpoint Security

  • Endpoint Detection and Response deployedSentinelOne EDR with behavioural and anomaly-based detection on all employee endpoints.
  • Mobile Device Management enforcedAll endpoints centrally managed through JumpCloud MDM.
  • Full-disk encryption enforced
  • Threat and malware protection enforced
  • Removable media and unauthorised peripherals blocked
  • Software installation restricted to approved applicationsInstalled software is reviewed quarterly by senior management.
  • Endpoints never connect directly to production

Corporate Security

  • Information Security Policy reviewed annually
  • Annual risk assessment and treatment
  • Asset management maintained
  • Code of conduct acknowledged by all personnel
  • Background screening performed
  • Security awareness and data privacy training
  • Board oversight of security and operations
  • Cyber liability insurance maintained

Incident Response

  • Incident Response Policy and program establishedDefined severity levels, roles, escalation procedures and communication protocols.
  • Customer notification within 24 hoursFor any incident that impacts, or is reasonably suspected to impact, customer data, security or service availability.
  • 24/7 security alerting to on-callAlerts from CloudTrail, GuardDuty, Coralogix, Okta and EDR are routed immediately for triage.
  • Root cause analysis for high-severity incidentsPrepared and reviewed by management.
  • Incident response procedures tested

Business Continuity

  • Business Continuity and Disaster Recovery plans established
  • Disaster recovery tested annuallyDrills include cyberattack-driven outage scenarios.
  • Automated encrypted backupsDaily backups replicated across three Availability Zones with cross-region replication, immutability and integrity checks.
  • Backup restoration tested annually

Availability

  • 99.5% availability SLA
  • Recovery Time Objective of 12 hours
  • Recovery Point Objective of up to 24 hours
  • Multi-AZ production architecture

Privacy

  • Data Protection Officer function establishedPrivacy is overseen by the Hush Legal team, acting as Data Protection Officer.
  • Compliance with GDPR, CCPA and the Israel Privacy Protection Law
  • Data subject rights supportedRequests for access, correction, deletion and objection, including the right to object to automated decision-making, are handled.
  • Data minimizationHush collects only the metadata needed to operate the platform; secret values are never stored.
  • Defined retention and secure deletionCustomer data is deleted within 30 days of contract termination, or earlier on request.

Vendor Management

  • Vendor risk assessment before onboarding
  • Ongoing monitoring of subservice organizationsManagement oversight confirms subservice organizations continue to operate in a controlled manner.
  • Contractual security and confidentiality terms with third parties