Third Party Index

Snapshot 19108

Document
Trust center
URL
https://trust.hypatos.ai/
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
350226 bytes
SHA-256 (raw)
2010aac3dc94b1e3ad1646088719157819b37723e8ac31100c8c39bf00930328
SHA-256 (normalized text)
22c92a04b5d75c871dcd2d9b8658d91bcf20297cc8022cca540b70fb193d73c9

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Start your security review
View & download sensitive information
Ask for information
Overview
At Hypatos, keeping our customers' documents and data safe sits at the core of everything we do.
Our security program is led by a dedicated team and built on an ISO 27001-certified ISMS, with ISO 27017 and ISO 27018 extensions for cloud and privacy. It is independently verified by a SOC 2 Type II attestation covering Security, Availability, and Confidentiality, with mappings to HIPAA and BSI C5. We process personal data in accordance with GDPR, and we make a completed CAIQ available on request for full transparency. Effectiveness is maintained through continuous monitoring in our compliance platform, reinforced by regular internal reviews, third-party audits, and independent penetration testing.
For more information, reach out to our Security team at [email protected].
Compliance
SOC 2 Type 2
ISO/IEC 27001:2022
ISO/IEC 27017:2015
ISO/IEC 27018:2019
GDPR
HIPAA
C5
CSA STAR Level 1
Hypatos is reviewed and trusted by
Experian
EON
Kärcher
KTM
Trench Group
Körber
Schwarz Gruppe
Strabag
Documents
COMPLIANCESOC 2 Type 2
COMPLIANCEISO/IEC 27001:2022
COMPLIANCEISO/IEC 27017:2015
COMPLIANCEISO/IEC 27018:2019
SELF-ASSESSMENTSCAIQ v4
REPORTSPen Test Executive Summary
REPORTSHigh-level Architecture Diagram
REPORTSISO 27001 Statement of Applicability
POLICIESAccess Control Policy
POLICIESBusiness Continuity/Disaster Recovery (BC/DR) Policy
POLICIESEncryption Policy
POLICIESInformation Security Policy
Policies
Information Security Policy
Access Control Policy
Business Continuity/Disaster Recovery (BC/DR) Policy
View more
Reports
Pen Test Executive Summary
ISO 27001 Statement of Applicability
High-level Architecture Diagram
Legal
Subprocessors
Self-Assessments
CAIQ v4
Product Security
We pay great attention to enterprise features such as access control and single sign on. We are happy to provide more details about our enterprise features upon request.
Data Security
We follow industry best practices for data security. We are happy to provide more details about our data security practices upon request.
App Security
We take application security seriously and are putting together a program to monitor internal apps.
AI
We take the usage of AI seriously in our organization and work to ensure security and reliability of the AI.
Data Privacy
Privacy of customer data is top of mind. We follow industry best practices and follow all applicable privacy regulations.
Access Control
Access is tightly monitored and controlled at our company. We are happy to provide more details about our access control practices upon request.
Infrastructure
We take great care to work with best-in-class infrastructure providers that provide secure computing and storage. We are happy to provide more details about our infrastructure upon request.
Endpoint Security
We follow industry best practices for endpoint security. We are happy to provide more details about our endpoint security practices upon request.
Network Security
We protect our corporate network against external & internal threats.
Corporate Security
We implement internal measures and practices to maintain a high standard of security.
Incident Response
We have a dedicated team that responds to security incidents. We are happy to provide more details about our incident response practices upon request.
Risk Management
We have a dedicated team that manages security risks. We are happy to provide more details about our risk management practices upon request.
Asset Management
We have strict asset management policies in place to ensure that all assets are accounted for and secure.
BC/DR
We have a business continuity plan in place to ensure that we can continue to operate in the event of a disaster.
Training
We provide security awareness training to all employees to ensure that they are aware of security best practices.
Change Management
We have a change and configuration management process in place to ensure that changes are properly reviewed and approved.
Continuous Monitoring
We continuously monitor our systems for security threats and vulnerabilities. We are happy to provide more details about our continuous monitoring practices upon request.
Subprocessors
Knowledge Base (FAQ)
How does Hypatos test its security, and how often?
Is data encrypted in transit as well as at rest?
Where is the Hypatos infrastructure hosted?
What are the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for your cloud services?
How does Hypatos handle incident response and breach notifications?
View more
If you think you may have discovered a vulnerability, please send us a note.
Report issue