Skip to content
HoopiHoopi
Security & compliance

Built for the review you are about to run

Access is granted connection by connection, credentials never leave our vault, every action is logged, and your data is never used to train a model. Here is the detail your security team will want.

SOC 2 Type IIGDPRCCPAHIPAA-readyISO 27001 (in progress)

Access you control, connection by connection

Every integration is authorized separately with the narrowest scope that works. Admins see what is connected, who connected it, and can revoke any of it in one click without breaking the rest.

Credentials you keep

Tokens are encrypted with per-tenant keys and never exposed in a prompt, a log or a response. Hoopi calls your systems as an authorized application, not by holding a password.

A complete record of what happened

Every request, every system call, every approval and every output is written to an audit log you can export or stream into your SIEM.

No training on your data, ever

Your documents, messages and outputs are excluded from model training by contract and by architecture. Enterprise customers can route inference to their own provider keys.

Isolation that is real

Each workspace runs in its own logical tenant with separate encryption keys. Enterprise plans can take a dedicated tenant, EU residency or a private network path.

Humans stay in the loop

Irreversible actions require named approvers. Read-only mode is always available. Nothing leaves your walls without someone saying yes.

Controls

The table your reviewer will ask for

EncryptionTLS 1.3 in transit, AES-256 at rest, per-tenant key derivation for credentials.
AuthenticationSAML 2.0 SSO, SCIM provisioning, enforced MFA, session policy controls.
AuthorizationRole-based permissions, per-connection scope, named approvers per action class.
LoggingImmutable audit events for every request, tool call, approval and output. Export or stream to SIEM.
IsolationLogical tenant separation by default; dedicated tenant or on-premise on Enterprise.
RetentionConfigurable retention windows; workspace deletion purges content and derived indexes.
TestingAnnual third-party penetration test, continuous dependency scanning, quarterly access reviews.
AvailabilityMulti-region redundancy, 99.9% uptime commitment on Enterprise, public status page.
Deployment

Run it where your policy requires

Most teams run on our multi-tenant cloud in a US region. Regulated environments have other options, and none of them are an afterthought.

  • Shared cloud — US regions by default, logical tenant isolation, per-tenant encryption keys.
  • Dedicated tenant — your own isolated environment with EU or custom residency.
  • Private network path — reach internal systems without exposing them to the internet.
  • On-premise — full deployment inside your perimeter for regulated industries.
  • Your model keys — route inference to your own provider, Azure OpenAI or Bedrock endpoint.

What we will send you

  • SOC 2 Type II reportUnder NDA, current period.
  • Penetration test summaryMost recent third-party assessment.
  • Data flow diagramWhere data goes, and where it does not.
  • DPA and sub-processor listSigned, with change notification terms.
  • Completed security questionnaireCAIQ or your own template.
  • Architecture review callWith the engineer who built it, not a rep.
Security questions

What reviewers ask us

No. Your content, credentials and outputs are never used to train any model. Data is encrypted in transit and at rest, and you can delete a workspace and its history at any time.

Hoopi asks before any irreversible action — external sends, payments, deletions, published posts. Your admins choose which actions need approval and who can give it. Connections can be left read-only indefinitely.

You do. Documents, dashboards, code and tools that Hoopi builds belong to your company, and you can export them at any time.

SAML SSO, SCIM provisioning, role-based permissions and exportable audit logs are included on Business and Enterprise plans.

In US regions by default, with EU residency available on Enterprise. Our sub-processor list is public and we notify customers before it changes.

Enterprise customers can run Hoopi in a dedicated tenant with a private network path to their systems. Full on-premise deployment is available for regulated industries on request.

Enterprise plans can route to your own provider keys or a private model endpoint, including Azure OpenAI and AWS Bedrock deployments.

Bring your hardest security question

We would rather answer it now than in month three. Book time with the team that built the access model.

$100 in credits included · Team plans from $100/month · Cancel any time