Trust Center

Security & Compliance

OpenHack is built by Titan Security Labs, Inc. Security is foundational to how we build and operate our platform. This page provides an overview of our compliance posture, security practices, and the third-party services we use.

Compliance Frameworks

HIPAA

Compliant

Business Associate Agreements available. OpenHack does not process PHI as a primary function but maintains HIPAA-aligned safeguards for healthcare customers.

GDPR

Compliant

EU data protection rights honored. Standard Contractual Clauses available for international transfers.

SOC 2 Type I

In Progress

Security, Confidentiality, and Availability trust principles. Audit underway with an accredited CPA firm.

ISO 27001

In Progress

Information security management system certification. Audit underway with an accredited certification body.

Security Practices

Core controls used to protect customer data and operate the OpenHack platform.

Data Security

  • Encryption at rest
  • Encryption in transit
  • Encrypted database backups
  • Source code deleted after scans

Access Control

  • Multi-factor authentication
  • Least-privilege access
  • Organization-scoped data access
  • Periodic access reviews

Application Security

  • Automated vulnerability scanning
  • Dependency monitoring
  • Web application firewall
  • CI/CD security checks

Monitoring & Response

  • CloudTrail audit logging
  • CloudWatch monitoring
  • Sentry error alerting
  • Incident response procedures

Endpoint Security

  • Full-disk encryption
  • Automatic device locking
  • Endpoint protection
  • Secure remote-work controls

Business Continuity

  • Multi-AZ production database
  • Point-in-time database recovery
  • Documented recovery procedures
  • Defined recovery objectives

Subprocessors

OpenHack uses a limited set of third-party subprocessors to deliver our services. We evaluate each provider's security practices and maintain contractual data protection obligations with every subprocessor.

SubprocessorPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure, compute, storage, database, loggingUS (us-west-2)
OpenRouterLLM inference for vulnerability analysisUS
Temporal TechnologiesWorkflow orchestrationUS
WorkOSAuthentication and SSOUS
StripePayment processingUS
PostHogProduct analyticsUS
SentryError monitoringUS
ResendTransactional emailUS
CloudflareDNS, CDN, and edge computeGlobal (edge)
GitHubSource control and webhooksUS

To subscribe to subprocessor change notifications, contact privacy@openhack.com.

Data Handling

Source Code

Customer source code is accessed read-only via authorized GitHub integrations. Code is downloaded temporarily for analysis and deleted after scan completion. OpenHack does not modify, fork, or retain copies of customer repositories.

AI & Model Training

Customer data is never used to train, fine-tune, or improve any AI models. LLM inference is performed via API calls that do not retain input data. OpenHack's AI analysis is stateless — no customer data persists in the inference pipeline.

Data Retention & Deletion

Scan findings are retained for the duration of the customer's subscription. Upon contract termination, all customer data is deleted within 30 days. Customers may request deletion at any time by contacting privacy@openhack.com.

Contact

For security questions, BAA requests, DPA inquiries, or to report a vulnerability: