The contact details your customers give you are yours. Hardtack is designed so our team can run your platform without browsing them.
Data is encrypted in transit and at rest.
Every operator's data is isolated at the database layer.
Passwordless sign-in, two-factor authentication available on operator accounts and required for our own staff, and confirmation on sensitive actions.
The AI proposes; you approve. Irreversible and high-dollar actions need your sign-off, and the voice agent never treats caller ID as proof of identity.
Encrypted off-site backups with tested restores.
Hardtack runs on US-hosted infrastructure. Live service status and incident history are published at status.hardtack.ai. Evaluating Hardtack and need a security questionnaire completed? Get in touch — that's separate from the vulnerability mailbox below.
Report security issues to security@hardtack.ai — please redact sensitive payloads in the email body; we'll move to a secure channel if needed. For routine support, write to support@hardtack.ai instead.
Safe harbor: good-faith research under this policy is authorized — we won't pursue legal action against researchers who avoid customer data and service disruption, report promptly, and hold public disclosure until we've fixed it.
In scope: app.hardtack.ai, api.hardtack.ai, hardtack.ai, the mobile driver app, and the voice-agent surface. Out of scope: social engineering, physical attacks, denial-of-service, and findings on third-party infrastructure — report those to the provider concerned. A machine-readable version of this policy lives at /.well-known/security.txt.
Evaluating Hardtack and need specifics? We’ll walk you through the details.
Get in touch