โ† Back to HexTyx

Trust Center

How HexTyx protects your data, secures our infrastructure, and operates with transparency.

Last updated: July 28, 2026  ยท  FAVZ Group  ยท  Wyoming, USA

Security & Privacy at a Glance

๐Ÿ”

Encryption at Rest

All sensitive fields encrypted with AES-128-CBC (Fernet). Target URLs and exploit payloads never stored in plaintext. Key rotation supported.

Active
๐Ÿ›ก๏ธ

Dual-Vault Architecture

Identity data (Vault A) and scan data (Vault B) are stored in completely separate databases. A breach of one vault cannot expose the other.

Active
๐Ÿ”’

Row-Level Security

Every database table enforces Postgres RLS. Users can only access their own data โ€” no query can return another user's records.

Active
๐ŸŒ

Encryption in Transit

All connections use TLS 1.3. API endpoints enforce HTTPS. Internal service communication is encrypted end-to-end.

Active
๐Ÿ•ต๏ธ

IP Anonymisation

IP addresses are never stored in plaintext. We store only a one-way SHA-256 hash. Google Analytics runs with IP anonymisation enabled.

Active
๐Ÿ”

No AI Training on Your Data

Your scan results, targets, and findings are never used to train AI models โ€” ours or our providers'. Your security data stays yours.

Guaranteed
โšก

99.5% Uptime SLA

Pro and Enterprise plans include a 99.5% monthly uptime SLA backed by our Railway deployment with automatic failover to Gemini fallback.

Pro+
๐Ÿ“‹

GDPR & CCPA Ready

Data export (Art. 20), right to erasure (Art. 17), and data portability are all implemented. DPA available on request for Enterprise customers.

Compliant
๐Ÿฅ

HIPAA BAA Available

Healthcare organisations can execute a Business Associate Agreement (BAA) with FAVZ Group for HIPAA-covered workloads.

Enterprise+

Legal & Compliance Documents

๐Ÿ”
Privacy Policy
How we collect, use, store, and protect your personal data. Covers GDPR, CCPA, and data retention periods.
Read โ†’
๐Ÿ“„
Terms of Service
The agreement governing your use of HexTyx, including authorisation requirements, billing, and liability.
Read โ†’
โœ…
Acceptable Use Policy
What you can and cannot do with HexTyx. The authorisation requirement and prohibited use cases.
Read โ†’
๐Ÿช
Cookie Policy
Which cookies we use, why, and how to control them. We use only essential and analytics cookies.
Read โ†’
๐Ÿ”—
Sub-processor List
Every third-party service that processes data on our behalf, their location, and their security certifications.
Read โ†’
๐Ÿฅ
Business Associate Agreement
HIPAA BAA for healthcare organisations. Available to Enterprise+ customers. Contact us to execute.
Read โ†’
๐Ÿ“ฆ
Open Source Licenses
Attribution for all open source software used in the HexTyx platform.
Read โ†’

Infrastructure & Sub-processors

Provider Purpose Location Certification Status
Anthropic AI inference (scan engine) USA SOC 2 Type II Operational
Supabase Database (Vault A + B) USA SOC 2 Type II, ISO 27001 Operational
Railway Application hosting USA SOC 2 Type II Operational
Stripe Payment processing USA PCI DSS Level 1, SOC 2 Operational
Vercel Frontend hosting Global CDN SOC 2 Type II Operational
Google (Analytics) Usage analytics (anonymised) USA / EU ISO 27001, SOC 2, GDPR Operational
Upstash / Redis Semantic cache + rate limiting USA SOC 2 Type II Operational
Google (Gemini) Fallback AI inference only USA ISO 27001, SOC 2 Fallback only
OpenAI QA Reviewer 2 (Enterprise) USA SOC 2 Type II Enterprise only

Security & Privacy Contacts

Security Issues
Vulnerability reports, responsible disclosure. We respond within 5 business days.
Privacy & Data Requests
GDPR/CCPA requests, data export, erasure, DPA enquiries. Response within 30 days.
Enterprise & Compliance
BAA execution, custom DPA, regulated industry onboarding, procurement questionnaires.
Legal Entity
FAVZ Group
Wyoming, USA  ยท  Governing law: Wyoming, USA