Hobbes Logo

Trust Center

Start your security review
View & download sensitive information
Ask for information
ControlK

Hobbes provides an AI agent for interactive product demonstrations. Security and privacy are part of how we design, operate, and monitor the service.

Hobbes has completed a SOC 2 Type II examination. We use encryption in transit and at rest, role-based access controls, documented development and incident-response processes, centralized monitoring, and regular risk reviews. Customers and qualified prospects can request access to our SOC 2 report, Data Processing Addendum, subprocessor register, and supporting security documents through this trust center.

Documents

DOCUMENTSMaster Subscription Terms

Risk Profile

Hobbes maintains a documented security and privacy risk-management program. We assess product, infrastructure, operational, and third-party risks, assign owners, track remediation, and review material risks as the service changes.

Product Security

Hobbes applies security controls throughout the product lifecycle. The service uses authenticated access, role-based permissions, organization-level data boundaries, encrypted communications, controlled production access, and logging for security-relevant activity.

Reports

Hobbes has completed a SOC 2 Type II examination. The current report is available to customers and qualified prospects through an approved trust-center access request.

Self-Assessments

Hobbes responds to reasonable customer security and privacy questionnaires. We first provide our SOC 2 Type II report and trust-center materials, then address questions not covered by those documents.

Data Security

Hobbes encrypts customer data in transit using TLS and at rest using managed encryption controls. Access follows least-privilege principles and is limited to authorized personnel with a business need. Hobbes maintains backups and documented retention and deletion processes.

App Security

Hobbes manages application changes through version control, peer review, automated validation, and controlled deployment workflows. We review dependencies and security findings, prioritize issues by severity and exposure, and track remediation to completion.

AI

Hobbes uses paid or commercial API offerings to provide AI inference, speech, and related product functions. We configure available provider controls so customer inputs and outputs are not used to train or improve providers' general-purpose models, unless a customer directs otherwise. Provider-specific retention for service delivery, security, abuse prevention, and legal compliance may apply. The current providers and processing purposes are listed in our gated subprocessor register.

Data Privacy

Hobbes generally acts as a processor or service provider when it handles personal data for a customer. Depending on customer configuration, this may include account information, demo interaction content, transcripts, contact details, IP addresses, device identifiers, and session or engagement metadata. Hobbes does not sell customer personal data or use it for cross-context behavioral advertising. International transfers use contractual or other legally recognized safeguards where required.

Access Control

Hobbes uses unique user identities, role-based permissions, least-privilege access, access reviews, and documented onboarding and offboarding procedures. Administrative access requires multi-factor authentication where supported and is limited to authorized personnel.

Infrastructure

Hobbes runs its production service on managed cloud infrastructure in the United States. Production systems use network isolation, encrypted storage, managed databases, restricted administrative access, backups, audit logging, and security monitoring. Hobbes does not operate its own data centers.

Endpoint Security

Devices used to access Hobbes systems must meet documented security requirements, including disk encryption, screen locking, supported software, and timely security updates. Access is removed promptly when a person's role changes or their relationship with Hobbes ends.

Network Security

Hobbes protects production traffic with TLS, firewall and web-application controls, network segmentation, restricted inbound access, and denial-of-service protections. Network and security events are logged and monitored for investigation.

Corporate Security

Hobbes maintains documented security responsibilities, confidentiality requirements, access-approval processes, onboarding and offboarding controls, security training, and vendor-risk reviews. Control operation is reviewed as part of the SOC 2 program.

Policies

Hobbes maintains written policies covering information security, access control, acceptable use, incident response, business continuity, change management, vendor management, and related operational controls. Policies are reviewed on a defined schedule and when material changes require an update. Detailed policies are available when appropriate through an approved access request.

Incident Response

Hobbes maintains a documented process to identify, investigate, contain, remediate, and learn from security incidents. We preserve relevant evidence, assign response responsibilities, and notify affected customers as required by applicable law and contract.

Risk Management

Hobbes periodically assesses security, privacy, operational, and third-party risks. Material findings receive an owner, severity, remediation plan, and target date, with progress tracked through completion.

Asset Management

Hobbes maintains inventories of systems and services that support the product. Assets have accountable owners, access restrictions, and lifecycle controls for provisioning, review, and decommissioning.

BC/DR

Hobbes maintains business-continuity and disaster-recovery procedures for material service disruptions. Production data is backed up using managed cloud controls, and recovery procedures are reviewed and tested on a defined schedule.

Training

Personnel complete security and privacy awareness training during onboarding and on a recurring basis. Training covers data handling, authentication, phishing, incident reporting, and responsibilities under company policies.

Change Management

Hobbes manages production changes through version control, review, automated checks, controlled deployment, and rollback procedures. Access to production deployment systems is restricted to authorized personnel.

Physical & Environment

Hobbes does not operate its own data centers. Physical and environmental protections for production infrastructure are provided by its audited cloud infrastructure providers. Hobbes applies documented security requirements to company workspaces and endpoints.

Continuous Monitoring

Hobbes uses centralized application, infrastructure, audit, threat-detection, and error-monitoring signals to identify abnormal or harmful activity. Alerts are triaged based on severity and investigated under documented operating procedures.