H
Trust · v1 draft

Security & Compliance

Version: v1 draft · Status: in effect at public launch · Last updated: 2026-05-13
Vendor review pack. Sub-processor list, data-flow diagram, vulnerability disclosure policy, and our current compliance questionnaire responses are available for vendor security reviews under NDA. Request via security@hypersave.ai — we typically respond within 1 business day.

Hypersave is built as a substrate for AI agents and operator-built applications. We treat security as a product-design constraint, not a post-launch retrofit. This page documents our current posture, compliance roadmap, and how to engage our security team.

Compliance posture

FrameworkStatus
SOC 2 Type IIPreparation underway alongside public launch. Report available under NDA on request once completed.
GDPR (EU)Data Processing Agreement available at /dpa. EU Standard Contractual Clauses used for cross-border transfers.
UK GDPRUK International Data Transfer Addendum applied where relevant.
Singapore PDPACompliant; Hypersave's operating entity is Singapore-registered.
EU AI Act (Article 53 GPAI substrate)We provide technical record-keeping primitives (per-request audit log, trace propagation, exportable usage data) for the operator's Article 12/14 obligations. We do not assume Article 6 high-risk-system obligations on the operator's behalf.
HIPAAOut of scope at launch. We do not currently sign BAAs. Customers must not submit PHI through the Service.

Technical controls

Operational controls

Application security

Sub-processors

Hypersave engages the following sub-processors in delivering the Service. This list is provided as our current and planned set; material changes are announced at least 30 days in advance.

CategorySub-processorPurpose
Payment processingStripeBilling, payment methods, invoicing, tax compliance
Inference upstreamsOpenAI, Anthropic, Google (Vertex AI), Together AI, DeepInfra, GroqRouted LLM and model inference
Compute upstreamsRunPod, Lambda Labs, Vast.ai, hyperscalers as partner enrolments complete (AWS, Azure, Google Cloud, Oracle Cloud)GPU pod and CPU sandbox provisioning
Hosting / edgeCloudflare, Fly.ioFrontend hosting, API edge, DNS, CDN, edge compute
Data storageSupabase (managed PostgreSQL), Cloudflare D1Account, billing, and usage records
ObservabilityProvider built-in metrics and logsService monitoring
Transactional emailResendReceipts, password reset, security and policy notices
MailboxFastmailInbound business email

Customers may request a current signed sub-processor list with subscription-to-changes notification at security@hypersave.ai.

Acceptable Use Policy

Use of the Service is subject to the following AUP. Prohibited workloads include but are not limited to:

Hypersave may suspend an account on reasonable belief of AUP violation, pending review.

Vulnerability disclosure

We welcome security research. Report suspected vulnerabilities to security@hypersave.ai. We commit to:

Scope. All Hypersave-operated services on hypersave.ai and its subdomains. Out of scope. Upstream provider infrastructure, third-party services, social engineering of Hypersave personnel, and denial-of-service attacks.

Abuse reports

To report Service abuse by another Hypersave customer (spam, malware, prohibited content), contact abuse@hypersave.ai with sufficient detail (timestamp, observed behaviour, evidence) for us to investigate.

Contact

General security questions, security review requests, or to request our compliance questionnaire responses: security@hypersave.ai.