Trust, by design.

Most security questions assume your data lives on a vendor's servers. With HeyOne AI, it lives on yours. That single architectural decision shapes how we approach every framework, control, and review below.

Overview

Almost nothing to hold. Nothing to leak.

Your AI agent runs on infrastructure you control, authenticated with your own provider keys. Operational data flows directly from your environment to the model you select. Once an agent is live, none of it returns to us.

This removes the risk most vendor security reviews exist to assess: a third party holding large volumes of your data. There is very little on our side to compromise, by design rather than by policy.

What follows is a precise account of the standards we meet, the controls we operate, and the documentation we provide to your security and procurement teams.

The data path

No middle to hide in. No moat to hide behind.

Your key. Your machine. Your call. The safest vendor database is the one that never exists. Your agent runs in your environment and talks to the model provider through your key. HeyOne designs, installs, and supports the system without becoming the place your work lives.

Your environment User 1 Web
Frameworks and standards

Every framework, met head-on.

SOC 2 & ISO 27001

Review on request

These audits evaluate how a vendor protects customer data held on its own systems. Because HeyOne AI stores almost none (your data remains in your environment and your keys connect to the model directly), the principal risk they assess is addressed at the architecture level. We do not currently hold SOC 2 or ISO 27001 attestation. For formal security reviews, we complete your questionnaire, provide a detailed walkthrough of our controls, and execute an NDA on request.

India's DPDP Act

Aligned

The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 govern personal data in our jurisdiction. HeyOne AI acts as the data fiduciary and you as the data principal. We meet our obligations for notice, purpose limitation, retention, and erasure, and support escalation to the Data Protection Board of India.

GDPR & UK GDPR

Aligned

For data subjects in the EU and UK, the GDPR and UK GDPR apply. Our lawful bases are legitimate interest for responding to enquiries and contract for active engagements. We honour access, rectification, erasure, and portability rights, and the right to lodge a complaint with your supervisory authority.

HIPAA & health data

By architecture

HIPAA is a United States healthcare statute; as an India-based provider, HeyOne AI is not a covered entity. For organisations handling protected health information, our default architecture (local or air-gapped deployment, with data remaining entirely within your environment) directly addresses the underlying requirement. We are glad to discuss a Business Associate Agreement where one is needed.

CCPA & global privacy

Aligned

Across California's CCPA and CPRA, Singapore's PDPA, Australia's Privacy Act, and comparable regimes, our commitments are consistent: we do not sell or share personal data, we minimise collection, and we honour access and deletion requests. Building to the strictest standard means one posture serves every region.

Cookies & Consent

No banner

Consent banners are required only for non-essential cookies used for tracking or advertising. HeyOne AI uses none. We run no analytics, issue no third-party requests, and self-host our fonts. The only value stored in your browser is your selected display theme, retained locally on your device.

Security controls

Controls we operate.

Beyond what we avoid holding, here is how we handle the limited data and access involved in a build, stated plainly, without diagrams or acronyms.

Data residency by default

Agents run on infrastructure you control, authenticated with your own provider keys. Your operational data travels directly from your environment to the model and never transits a HeyOne system.

Encryption and access governance

Internal working notes are encrypted at rest within accounts secured by multi-factor authentication. Every team member uses an individual login. We operate no shared credentials, so all access is attributable.

Least-privilege, time-bound access

Any access you grant for an engagement is scoped to the work, reviewed during the project, and revoked on completion. Materials you share are deleted on request, with written confirmation.

72-hour breach notification

In the event of an incident on our side, we commit to notifying you within 72 hours in clear, actionable language. This aligns with both India's DPDP and the GDPR, so one standard serves every customer.

Coordinated disclosure

We publish a security.txt contact under RFC 9116, giving researchers a defined channel to report a vulnerability directly and responsibly, rather than guessing where to send it.

Air-gapped deployment option

For workloads that must never reach an external provider, we deploy a self-hosted open-source model that runs entirely within your environment. Data never leaves your premises.

For security and procurement teams

What we provide for review.

We support security and vendor due-diligence processes directly. The following are available on request, under NDA.

  • A completed security questionnaire in your own format, with a guided walkthrough of our controls.
  • A mutual NDA executed before any environment-specific discussion.
  • A written 72-hour breach-notification commitment, aligned to DPDP and GDPR.
  • A documented data-deletion process, with written confirmation on completion.
  • A Business Associate Agreement discussion for US covered entities handling health data.
  • A reference architecture for local-first, bring-your-own-key deployment.

Bring us your
security review.

Send your security questionnaire or due-diligence requirements. We respond within four hours, with an NDA in place on request.