Security

Security, built in
from the studs.

Operators trust Hardtack with their customers, their routes, and their books. Here's how we protect that data — and how to report a problem if you find one.
The core promise

Your customers' data stays yours.

Built so your data stays yours

The contact details your customers give you are yours. Hardtack is designed so our team can run your platform without browsing them.

Posture

How the platform is built.

🔐
Encryption

Data is encrypted in transit and at rest.

🧱
Tenant isolation

Every operator's data is isolated at the database layer.

🔑
Access control

Passwordless sign-in, two-factor authentication available on operator accounts and required for our own staff, and confirmation on sensitive actions.

🤖
AI guardrails

The AI proposes; you approve. Irreversible and high-dollar actions need your sign-off, and the voice agent never treats caller ID as proof of identity.

💾
Backups & recovery

Encrypted off-site backups with tested restores.

Hardtack runs on US-hosted infrastructure. Live service status and incident history are published at status.hardtack.ai. Evaluating Hardtack and need a security questionnaire completed? Get in touch — that's separate from the vulnerability mailbox below.

Responsible disclosure

Found something? Tell us.

Report security issues to security@hardtack.ai — please redact sensitive payloads in the email body; we'll move to a secure channel if needed. For routine support, write to support@hardtack.ai instead.

Safe harbor: good-faith research under this policy is authorized — we won't pursue legal action against researchers who avoid customer data and service disruption, report promptly, and hold public disclosure until we've fixed it.

Scope

What's in and out.

In scope: app.hardtack.ai, api.hardtack.ai, hardtack.ai, the mobile driver app, and the voice-agent surface. Out of scope: social engineering, physical attacks, denial-of-service, and findings on third-party infrastructure — report those to the provider concerned. A machine-readable version of this policy lives at /.well-known/security.txt.

QUESTIONS?

Talk to us
about security.

Evaluating Hardtack and need specifics? We’ll walk you through the details.

Get in touch