Trust Center

We take only the access we need.

A security awareness program should not become a security risk. This page sets out how we protect your organization's data, who helps us run the service, and where we stand on compliance. If a question is not answered here, ask us and we will answer it.

Security controls

What is in place today.

Each of these is how the product works now, not a plan.

01 / ACCESS

Least access by design

Simulations, training and the Report phishing button need no access to anyone's mailbox. We read your directory to know who to train, and nothing more.

Mailbox access is opt-in. You grant it only to place simulations straight into inboxes or to remove a confirmed phishing email, and we use it only for that.

02 / SIGN-IN

Two-factor on every account

Every console account must use two-factor sign-in. There is no way to skip it.

Single sign-on with Microsoft or Google is available, and your organization can require it. Passwords are at least 12 characters.

03 / SESSIONS

Sessions that end

A console session signs out after 30 minutes without activity and 12 hours after sign-in, however active. Signing out in one tab signs out the others.

04 / ENCRYPTION

Encrypted in transit and at rest

All traffic uses TLS. The database is encrypted at rest with AES-256, including its replicas and backups.

Backups run continuously, so the database can be restored to a point in time.

05 / ROLES

Roles and an audit trail

Owner, admin and viewer roles control who can change what. Important actions, such as consent, campaign launches, training assignments and deletions, are written to an audit log the application never changes or deletes, even when an organization is removed.

API keys are limited to the permissions you choose, shown once, and can be revoked at any time.

06 / SEPARATION

Your data stays yours

Each organization's data is kept apart in the database and in the application. Our sales and support staff have no access to customer organization data.

07 / SIMULATIONS

Nothing typed is kept

When someone types into a simulated sign-in page, we never store what they typed. We record only that it happened, so they can be offered training.

08 / AI

No AI training on your data

Our AI features run on Anthropic's commercial service, which does not train its models on customer content. We do not either.

AI verdicts on reported emails are advisory. A person on your team makes the call.

09 / PAYMENTS

Card details never touch us

Card payments go straight to Stripe. Your card number never reaches our servers.

Subprocessors

Who helps us run the service.

These are the companies that process customer data on our behalf. All of them are in the United States.

CompanyWhat it does for usLocation
RenderHosts the application and the database that holds customer data.US (Oregon)
VultrHosts the mail server we run to send simulation emails.US (Atlanta, Georgia)
ResendSends account emails, such as invitations, notifications and scheduled reports. It does not send simulations.US
AnthropicRuns the AI features: the console assistant, drafting templates, and assessing reported emails.US
StripeTakes card payments and manages subscriptions. It holds billing details, never your people's data.US

Your own Microsoft 365 or Google Workspace is your system, not our subprocessor. We act in it only with the permissions you grant. We will give notice before adding or changing a subprocessor.

Compliance

Where we stand, said plainly.

We are a young company. We would rather tell you exactly what we have than imply more.

In place

  • Written security program. An Information Security Policy and an Incident Response Plan.
  • Cyber liability insurance. A certificate is available on request.

Not yet

  • SOC 2. We have not started a SOC 2 audit and do not hold a report.
  • Independent penetration test. Not yet performed.
Documents

Available on request.

Ask and we will send any of these. Several are also part of the agreement you sign with us.

Request Documents → Privacy Policy
Report a security issue

Found something? Tell us.

  • Email us with what you found and how to reproduce it.
  • We will confirm we received it and keep you updated until it is fixed.
  • Please give us a reasonable time to fix it before telling anyone else, and do not access, change or delete other people's data while testing.
  • For a suspected incident affecting your organization, email the same address and your account contact.
Security contact
security@thehumanvector.io

Also published at /.well-known/security.txt

Last updated 10/07/2026