Security

Security built for agentic systems.

Hyperstruck protects customer data, agent configuration, learnings, credentials, and operational context with layered technical and operational controls.

Last updated: 2 June 2026

Defense in depth

Layered controls cover authentication, authorization, tenant isolation, application logic, infrastructure, and operational access.

Tenant isolation

Access is scoped to authenticated users and tenant membership, with tenant boundaries enforced by database row-level security.

Enterprise SSO

Enterprise customers can authenticate through their company identity provider so access follows central SSO and offboarding policies.

Encryption

Data is encrypted in transit using TLS 1.3+ and at rest using AES-256 where supported by the underlying managed infrastructure.

Resilience

Operational database backups are performed daily to support recovery from operational failure.

AI data protections

PII redaction or masking and prompt injection protections reduce the risk of sensitive data exposure or malicious instructions.

Secure workstations

Team workstations are configured with encryption by default to reduce the risk from lost or stolen devices.

AI and subprocessor handling

Customer data is processed by subprocessors only for the purposes needed to provide Hyperstruck. AI subprocessors do not train models on customer data.

Default processing is treated as having subprocessor retention of up to 30 days. Shorter provider commitments may apply, but Hyperstruck presents 30 days as the conservative baseline.

Customers may bring their own LLM keys. In those cases, the connected provider's terms, retention rules, and data processing commitments apply to that usage.

Report a vulnerability

Security vulnerabilities and data protection issues can be reported with enough detail for investigation.

security@hyperstruck.com