Security | Hobglobin
ISO 27001 certified · SOC 2 Type II attested.
Your data stays in your tenancy, in your region. Engineering team in Bengaluru, working your business hours. On-site for kickoff and operator review.
Deployment models
- Customer cloud: the workflow runs in your tenancy, in your region.
- On-premise, including air-gapped or OT-isolated networks when that is the boundary.
- Data residency: documents and indexes stay where your regulators expect them.
How engineers in India access client data
Client-issued, logged accounts. No copies leave the client environment.
Certifications
ISO 27001 is a certification. SOC 2 Type II is an auditor attestation report, not a certificate. Request both under NDA at hobglobin.com/security. Issuing body, scope, validity dates, and the Type II audit period are included with the artefacts.
Policy summary
- Access is named, logged, and time-bounded.
- Human reviewers approve safety, regulatory, and operational outputs.
- Critical actions can be rolled back.
- Audit logs cover queries, sources, and reviewer decisions.
Subprocessors
- Google Cloud / Firebase: website contact, assessment, and security-request forms.
- Vercel: hosting and cookieless analytics.
- LLM providers in your tenancy: inference for client workflows. We do not train foundation models on your corpus.
Security contact
security@hobglobin.com for security reviews. hello@hobglobin.com for everything else.