Flow-down restrictions
On defence and government adjacent projects, obligations arrive through the main contract rather than through your own policies. They commonly limit which sub-processors may touch project data, where that data may be hosted, and who may be granted access.
Those constraints are treated as inputs to deployment rather than exceptions to it. Where an external processor is not permitted, Hecato is deployed inside your environment. Where it is, hosting region and sub-processor list are agreed in writing before any record is shared.
What we will not claim
Hecato AI holds no security certification at the time of writing. When an audit is complete the report will be named here and made available under NDA. Until then, treat any assurance on this page as a contractual commitment we will make in writing rather than as a third party attestation.
We would rather lose a procurement round on a missing certificate than pass one on a claim that does not survive diligence.
Reporting something
If you believe you have found a vulnerability, email us at security@hecato.ai and we will acknowledge within two working days.
- Please do not include client project data in your report.
- Provide enough detail for us to reproduce the issue.
Questions from procurement go to hello@hecato.ai.