SOC 2 & ISO 27001
Review on request
These audits evaluate how a vendor protects customer data held on its own systems. Because HeyOne AI stores almost none (your data remains in your environment and your keys connect to the model directly), the principal risk they assess is addressed at the architecture level. We do not currently hold SOC 2 or ISO 27001 attestation. For formal security reviews, we complete your questionnaire, provide a detailed walkthrough of our controls, and execute an NDA on request.
India's DPDP Act
Aligned
The Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 govern personal data in our jurisdiction. HeyOne AI acts as the data fiduciary and you as the data principal. We meet our obligations for notice, purpose limitation, retention, and erasure, and support escalation to the Data Protection Board of India.
GDPR & UK GDPR
Aligned
For data subjects in the EU and UK, the GDPR and UK GDPR apply. Our lawful bases are legitimate interest for responding to enquiries and contract for active engagements. We honour access, rectification, erasure, and portability rights, and the right to lodge a complaint with your supervisory authority.
HIPAA & health data
By architecture
HIPAA is a United States healthcare statute; as an India-based provider, HeyOne AI is not a covered entity. For organisations handling protected health information, our default architecture (local or air-gapped deployment, with data remaining entirely within your environment) directly addresses the underlying requirement. We are glad to discuss a Business Associate Agreement where one is needed.
CCPA & global privacy
Aligned
Across California's CCPA and CPRA, Singapore's PDPA, Australia's Privacy Act, and comparable regimes, our commitments are consistent: we do not sell or share personal data, we minimise collection, and we honour access and deletion requests. Building to the strictest standard means one posture serves every region.
Cookies & Consent
No banner
Consent banners are required only for non-essential cookies used for tracking or advertising. HeyOne AI uses none. We run no analytics, issue no third-party requests, and self-host our fonts. The only value stored in your browser is your selected display theme, retained locally on your device.