Version 16 July 2026

Security overview

A concise overview of controls used to protect hiddenhand customer work. Detailed assurance material is available during pilot onboarding.

Access

  • Authenticated access with tenant and project authorization enforced by the backend.
  • Organization and project roles with immediate access revocation.
  • Multi-factor and fresh-authentication requirements for hiddenhand administrative actions.
  • No customer impersonation capability.

Files and processing

  • Private quarantine before processing, file signature and resource-limit validation, and malware scanning that fails closed in production.
  • Encrypted transport and private object storage with authorized access paths.
  • Durable jobs with idempotency, cancellation, bounded retries, and no authoritative partial result on failure.
  • Financial and identity-value redaction from model-bound text where the value is not needed for the requested workflow.

Monitoring and response

  • Structured, correlated logs with customer-content redaction.
  • Restricted operational dashboards and audited administrative actions.
  • Health checks for application, database, queue, worker, and storage dependencies.
  • Incident triage and recovery procedures for processing, access, billing, and deletion issues.

Customer responsibilities

  • Use supported business documents and avoid prohibited sensitive datasets.
  • Review memberships regularly and remove departed users.
  • Verify generated results against source documents before relying on them.
  • Report suspected security issues to support@hellohiddenhand.com.