/ Security

Commitments, not certifications

This page states what Hecato AI will contractually commit to. It does not claim third-party attestations we do not yet hold.

Posture
Data residency
Hosting region agreed at deployment, against any restrictions that apply to the bid documents.
Deployment model
Available inside your own environment where data classification prohibits an external processor.
Access
Permissioned by role and by bid. Teams see what their role allows and nothing else.
Training
Project data is not used to train models for other customers.
Audit
Output is source linked, so every finding traces to the document, page and section it came from.
Retention
Retention period and deletion on exit are set in the agreement rather than assumed.

Flow-down restrictions

On defense and government adjacent projects, obligations can arrive through the bid documents and procurement terms rather than through your own policies. They commonly limit which sub-processors may touch bid data, where that data may be hosted, and who may be granted access.

Those constraints are treated as inputs to deployment rather than exceptions to it. Where an external processor is not permitted, Hecato is deployed inside your environment. Where it is, hosting region and sub-processor list are agreed in writing before any record is shared.

Reporting something

If you believe you have found a vulnerability, email us at security@hecato.ai and we will acknowledge within two working days.

  • Please do not include client bid data in your report.
  • Provide enough detail for us to reproduce the issue.

Questions from procurement go to hello@hecato.ai.