Hush Security’s Trust Center Ask a question

Hush Security – Enterprise Security for Enterprise AI Agents

Product Security

Updated Oct 7, 2026

How the Hush platform is built, operated and governed to protect the agents, identities and environments it connects to.

Secure Development

  • Threat modelling and design review for every new feature
  • Security analysis and senior review on every pull request
  • SAST, DAST, SCA, secrets and container scanning on every change
  • Critical and High vulnerabilities blocked from reaching production
  • Container base images rebuilt at least monthly

Product Authentication & Access

  • SAML 2.0 single sign-on supported
  • SCIM and SAML-based provisioning and de-provisioning supported
  • Two-factor authentication for administrators
  • Role Based Access Control (RBAC) enforced in-product
  • Self-service console for security settings, access logs and security events

AI Security & Guardrails

  • AI models accessed exclusively through Amazon Bedrock with guardrails on prompts and outputs
  • Zero data retention and zero training at the model provider
  • No customer data used for model training or fine-tuning
  • AI outputs are advisory onlyAI never triggers automations, grants access or changes security configurations.
  • Human review before any operational decisionAI behaviour is monitored for accuracy, performance degradation and anomalies.

Tenant Isolation & Data Protection

  • Strict multi-tenant isolation, validated by annual penetration testing
  • Secret values never stored — metadata only
  • Encryption in transit and at rest (TLS 1.3 / mTLS, AES-256 under AWS KMS)
  • No production customer data in development, test or QA
  • Customer data deleted within 30 days of termination, or earlier on request

Infrastructure & Deployment Security

  • AWS us-east-1 across multiple Availability Zones
  • Infrastructure as Code (Terraform) on Kubernetes with automated rollback
  • Segmented network with databases in private subnets
  • AWS WAF (OWASP Core Rule Set), rate limiting and DDoS protection
  • Continuous threat detection with Amazon GuardDuty
  • Production administration only via AWS Systems Manager Session Manager

Auditability

  • End-to-end audit logs across application, API, infrastructure, database, network and access layers
  • Logs centralised in Coralogix, outside production, with immutability controls
  • Every agent and identity action attributed to an accountable owner
  • Audit log data available to customers on request