A CHATTAN brand · AI that doesn't break
// Security

Security, built in
from the studs.

Operators trust Hardtack with their customers, their routes, and their books. Here's how we protect that data — and how to report a problem if you find one.
// The core promise

Your customers' data stays yours.

Built so your data stays yours

The contact details your customers give you — names, phone numbers, addresses — are yours. Hardtack is designed so our team can run your platform without browsing them: admin and support surfaces show aggregated and tokenized data, with PII redaction enforced in code at the read layer. The trust boundary lives in the system, not just in a policy we promise to follow.

// Posture

How the platform is built.

Security isn't a page we bolt on at launch — it's how the system is put together. The essentials:

🔐
Encryption

TLS in transit; sensitive customer fields — names, phones, emails — encrypted at rest.

🧱
Tenant isolation

Every operator's data is fenced at the database with Postgres row-level security — not just in the app layer.

🔑
Access control

Passwordless magic-link sign-in, mandatory two-factor (TOTP) for admins, HttpOnly session cookies, and step-up confirmation on sensitive actions. The app itself connects with a least-privilege database role.

🤖
AI guardrails

The AI proposes; you approve. Irreversible and high-dollar actions are bounded in code and need your sign-off — and the voice agent never treats caller ID as proof of identity.

💾
Backups & recovery

Daily encrypted, off-site backups plus point-in-time recovery, with restores periodically tested.

🛡️
Vendor data handling

We configure AI model vendors to disable training on your data and turn on available logging opt-outs, and we redact PII before it reaches a model.

// Data, privacy & residency

What we hold, and your rights.

  • Retention & deletion. We keep your data only as long as needed — with specific retention windows in our Privacy Policy — and delete it on request.
  • Your rights. We honor CCPA / CPRA rights — and, to the extent laws like the GDPR apply to you, their equivalents — see our Privacy Policy; a Data Processing Addendum is available on request.
  • Residency. Hardtack runs on US-hosted infrastructure.
  • Incident notification. If a security incident affects your data, we'll notify you without undue delay.
// Certifications & assurances

Where we stand.

We've completed a full security review and remediate findings on a defined timeline (see below). We maintain a current list of sub-processors and their data-handling terms, available on request. A SOC 2 audit is on our roadmap; what's described above is what the platform does today.

Evaluating Hardtack and need security details or a questionnaire completed? Get in touch — that's separate from the vulnerability mailbox below.

// Responsible disclosure

Found something? Tell us.

Hardtack runs a Vulnerability Disclosure Program. Report security issues to security@hardtack.ai — please redact sensitive payloads in the email body; we'll move to a secure channel if needed. PGP isn't published yet. For routine support, write to support@hardtack.ai instead.

// Our commitment

What you can expect back.

  • We aim to acknowledge within 72 hours (business days).
  • Triage within about 7 days of acknowledgement.
  • Remediation timeline based on severity and complexity for accepted findings.
  • Safe harbor: good-faith research under this policy is authorized — we won't pursue legal action against researchers who avoid customer data and service disruption, report promptly, and hold public disclosure until we've fixed it.

This is a coordinated-disclosure policy, not a paid bug-bounty program — but every credible report gets a personal acknowledgement and, with your permission, credit in the post-fix advisory.

// Scope

What's in and out.

In scope: app.hardtack.ai, api.hardtack.ai, hardtack.ai, the mobile driver app, and the voice-agent surface. Out of scope: social engineering, physical attacks, denial-of-service, and findings on third-party infrastructure (Twilio, Stripe, and the like) — report those to the upstream provider. A machine-readable version of this policy lives at /.well-known/security.txt.

// QUESTIONS?

Talk to us
about security.

Evaluating Hardtack and need specifics? We’ll walk you through the details.

Get in touch