Built for the review you are about to run
Access is granted connection by connection, credentials never leave our vault, every action is logged, and your data is never used to train a model. Here is the detail your security team will want.
Access you control, connection by connection
Every integration is authorized separately with the narrowest scope that works. Admins see what is connected, who connected it, and can revoke any of it in one click without breaking the rest.
Credentials you keep
Tokens are encrypted with per-tenant keys and never exposed in a prompt, a log or a response. Hoopi calls your systems as an authorized application, not by holding a password.
A complete record of what happened
Every request, every system call, every approval and every output is written to an audit log you can export or stream into your SIEM.
No training on your data, ever
Your documents, messages and outputs are excluded from model training by contract and by architecture. Enterprise customers can route inference to their own provider keys.
Isolation that is real
Each workspace runs in its own logical tenant with separate encryption keys. Enterprise plans can take a dedicated tenant, EU residency or a private network path.
Humans stay in the loop
Irreversible actions require named approvers. Read-only mode is always available. Nothing leaves your walls without someone saying yes.
The table your reviewer will ask for
Run it where your policy requires
Most teams run on our multi-tenant cloud in a US region. Regulated environments have other options, and none of them are an afterthought.
- Shared cloud — US regions by default, logical tenant isolation, per-tenant encryption keys.
- Dedicated tenant — your own isolated environment with EU or custom residency.
- Private network path — reach internal systems without exposing them to the internet.
- On-premise — full deployment inside your perimeter for regulated industries.
- Your model keys — route inference to your own provider, Azure OpenAI or Bedrock endpoint.
What we will send you
- SOC 2 Type II reportUnder NDA, current period.
- Penetration test summaryMost recent third-party assessment.
- Data flow diagramWhere data goes, and where it does not.
- DPA and sub-processor listSigned, with change notification terms.
- Completed security questionnaireCAIQ or your own template.
- Architecture review callWith the engineer who built it, not a rep.
What reviewers ask us
No. Your content, credentials and outputs are never used to train any model. Data is encrypted in transit and at rest, and you can delete a workspace and its history at any time.
Hoopi asks before any irreversible action — external sends, payments, deletions, published posts. Your admins choose which actions need approval and who can give it. Connections can be left read-only indefinitely.
You do. Documents, dashboards, code and tools that Hoopi builds belong to your company, and you can export them at any time.
SAML SSO, SCIM provisioning, role-based permissions and exportable audit logs are included on Business and Enterprise plans.
In US regions by default, with EU residency available on Enterprise. Our sub-processor list is public and we notify customers before it changes.
Enterprise customers can run Hoopi in a dedicated tenant with a private network path to their systems. Full on-premise deployment is available for regulated industries on request.
Enterprise plans can route to your own provider keys or a private model endpoint, including Azure OpenAI and AWS Bedrock deployments.
Bring your hardest security question
We would rather answer it now than in month three. Book time with the team that built the access model.
$100 in credits included · Team plans from $100/month · Cancel any time

