Hobbes provides an AI agent for interactive product demonstrations. Security and privacy are part of how we design, operate, and monitor the service.
Hobbes has completed a SOC 2 Type II examination. We use encryption in transit and at rest, role-based access controls, documented development and incident-response processes, centralized monitoring, and regular risk reviews. Customers and qualified prospects can request access to our SOC 2 report, Data Processing Addendum, subprocessor register, and supporting security documents through this trust center.
Risk Profile
Hobbes maintains a documented security and privacy risk-management program. We assess product, infrastructure, operational, and third-party risks, assign owners, track remediation, and review material risks as the service changes.
Product Security
Hobbes applies security controls throughout the product lifecycle. The service uses authenticated access, role-based permissions, organization-level data boundaries, encrypted communications, controlled production access, and logging for security-relevant activity.
Reports
Hobbes has completed a SOC 2 Type II examination. The current report is available to customers and qualified prospects through an approved trust-center access request.
Self-Assessments
Hobbes responds to reasonable customer security and privacy questionnaires. We first provide our SOC 2 Type II report and trust-center materials, then address questions not covered by those documents.
Data Security
Hobbes encrypts customer data in transit using TLS and at rest using managed encryption controls. Access follows least-privilege principles and is limited to authorized personnel with a business need. Hobbes maintains backups and documented retention and deletion processes.
App Security
Hobbes manages application changes through version control, peer review, automated validation, and controlled deployment workflows. We review dependencies and security findings, prioritize issues by severity and exposure, and track remediation to completion.
AI
Hobbes uses paid or commercial API offerings to provide AI inference, speech, and related product functions. We configure available provider controls so customer inputs and outputs are not used to train or improve providers' general-purpose models, unless a customer directs otherwise. Provider-specific retention for service delivery, security, abuse prevention, and legal compliance may apply. The current providers and processing purposes are listed in our gated subprocessor register.
Data Privacy
Hobbes generally acts as a processor or service provider when it handles personal data for a customer. Depending on customer configuration, this may include account information, demo interaction content, transcripts, contact details, IP addresses, device identifiers, and session or engagement metadata. Hobbes does not sell customer personal data or use it for cross-context behavioral advertising. International transfers use contractual or other legally recognized safeguards where required.
Access Control
Hobbes uses unique user identities, role-based permissions, least-privilege access, access reviews, and documented onboarding and offboarding procedures. Administrative access requires multi-factor authentication where supported and is limited to authorized personnel.
Infrastructure
Hobbes runs its production service on managed cloud infrastructure in the United States. Production systems use network isolation, encrypted storage, managed databases, restricted administrative access, backups, audit logging, and security monitoring. Hobbes does not operate its own data centers.
Endpoint Security
Devices used to access Hobbes systems must meet documented security requirements, including disk encryption, screen locking, supported software, and timely security updates. Access is removed promptly when a person's role changes or their relationship with Hobbes ends.
Network Security
Hobbes protects production traffic with TLS, firewall and web-application controls, network segmentation, restricted inbound access, and denial-of-service protections. Network and security events are logged and monitored for investigation.
Corporate Security
Hobbes maintains documented security responsibilities, confidentiality requirements, access-approval processes, onboarding and offboarding controls, security training, and vendor-risk reviews. Control operation is reviewed as part of the SOC 2 program.
Policies
Hobbes maintains written policies covering information security, access control, acceptable use, incident response, business continuity, change management, vendor management, and related operational controls. Policies are reviewed on a defined schedule and when material changes require an update. Detailed policies are available when appropriate through an approved access request.
Incident Response
Hobbes maintains a documented process to identify, investigate, contain, remediate, and learn from security incidents. We preserve relevant evidence, assign response responsibilities, and notify affected customers as required by applicable law and contract.
Risk Management
Hobbes periodically assesses security, privacy, operational, and third-party risks. Material findings receive an owner, severity, remediation plan, and target date, with progress tracked through completion.
Asset Management
Hobbes maintains inventories of systems and services that support the product. Assets have accountable owners, access restrictions, and lifecycle controls for provisioning, review, and decommissioning.
BC/DR
Hobbes maintains business-continuity and disaster-recovery procedures for material service disruptions. Production data is backed up using managed cloud controls, and recovery procedures are reviewed and tested on a defined schedule.
Training
Personnel complete security and privacy awareness training during onboarding and on a recurring basis. Training covers data handling, authentication, phishing, incident reporting, and responsibilities under company policies.
Change Management
Hobbes manages production changes through version control, review, automated checks, controlled deployment, and rollback procedures. Access to production deployment systems is restricted to authorized personnel.
Physical & Environment
Hobbes does not operate its own data centers. Physical and environmental protections for production infrastructure are provided by its audited cloud infrastructure providers. Hobbes applies documented security requirements to company workspaces and endpoints.
Continuous Monitoring
Hobbes uses centralized application, infrastructure, audit, threat-detection, and error-monitoring signals to identify abnormal or harmful activity. Alerts are triaged based on severity and investigated under documented operating procedures.

