Skip to main content
HNTIC

Security
HNTIC

We design for data privacy, information security and legal compliance from the first line of code.

Certifications and compliance

SOC 2 Type II-certified infrastructure

HNTIC runs exclusively on SOC 2 Type II-certified providers, which covers security, availability and confidentiality.

GDPR compliant

We comply with the General Data Protection Regulation and sign standard contractual clauses (SCCs) with every subprocessor.

ISO 27001-certified hosting

Your workspace is hosted on ISO 27001-certified infrastructure for information security management.

Security measures

Your data stays yours

No customer data trains AI models. A zero data retention policy is available.

End-to-end encryption

AES-256 at rest, TLS 1.2+ in transit. Every customer runs in an isolated architecture.

SSO, SAML & SCIM

Single sign-on through SAML 2.0 and OpenID Connect. Roles and permissions stay in sync automatically.

Data residency

European hosting options for teams with data sovereignty requirements.

Full control over access

Granular permissions per document, collection and integration. Least privilege applies everywhere.

Audit and traceability

Complete logging of access and actions. Compliance reports available on request.

“HNTIC puts us in control of the AI. We decide exactly which data it can reach and tune the settings to our own compliance requirements.”
Marc D.

Marc D.

Operations Director · Manufacturing

Frequently asked questions

How we handle security

We run exclusively on SOC 2 Type II-certified providers, and your workspace is hosted on ISO 27001-certified infrastructure. On top of that: end-to-end encryption, an isolated architecture per customer, strict access controls and regular audits.

Least privilege and role-based permissions govern every account, so nobody reaches a system or a process they have no business in. Multi-factor authentication guards anything holding highly confidential data.

For physical access to core systems, we rely on leading data center and cloud infrastructure providers. Their facilities have around-the-clock monitoring and biometric access control.

People authorized to use HNTIC only reach the data their access rights cover. Passwords are hashed and salted, recovery and validation follow current best practice, and partners can log in through SSO.

Nobody unauthorized can read, copy, change or delete personal data while it moves across a network or sits on a storage medium. We encrypt data at rest with AES-256 and data in transit with TLS 1.2+.

We review and assess risk on a set schedule. We track how closely our policies and procedures are followed, and we keep a risk register current and approved by management.

We shield our IT infrastructure from malicious code with several layers of protection. Active monitoring confirms antivirus and spam filters stay on and current, we install security updates as they ship, and every employee takes security training at least once a year.

Our team is what matters most, and we hire the best people we can find anywhere. Everyone at HNTIC works under guidelines covering confidentiality, professional ethics and professional standards, which keep us in line with the law and with the terms of our vendor and customer agreements.

We train our ranking and query-rewriting algorithm on a dedicated internal dataset, manually and automatically, so it surfaces the closest matches. Customer data — external content our service indexes, for instance — never leaves the isolated tenant unless you agree to it specifically. To be clear: no customer data trains third-party LLMs.

Anything added through an integration or uploaded to the platform is indexed and stored on our cloud instance.

Customer data stays strictly isolated. Every organization gets its own partitioned space. Data at rest is encrypted with AES-256 and data in transit with TLS 1.2+.

Documents reach the platform three ways: direct upload, a private integration or a shared integration. What a given person can open depends on the route the document took and on your admin settings.

For direct uploads, you manage access inside the platform, document by document or through collections.

For private integrations, each user authenticates individually and only sees results their own permissions already cover.

For shared integrations, admins decide which documents are available to everyone with access to a collection, to the whole workspace or both.

The platform is agnostic about the large language models underneath it. HNTIC offers third-party LLM options that are not trained on content data. We put enterprise security agreements in place with those vendors and, wherever it is offered, a zero data retention (ZDR) policy. No customer data trains third-party LLMs.

Yes. You decide which integrations your organization can use, and which ones feed the platform's natural language answers.

HNTIC employees have no access to your workspace by default, and they only get in if you invite them. An invited HNTIC employee cannot open a file without specific permission and never sees search queries.