Hicap Security Commitment
Effective Date: January 1, 2026
Last Updated: July 22, 2026
Security by design
Security is core to how Hicap builds and operates AI infrastructure. We design our systems so customer prompts and completions flow through without being stored, encrypt everything in transit and at rest, and continuously monitor for threats.
Zero prompt retention
Hicap does not store customer prompts or AI model responses. Requests are forwarded to the selected model provider and responses are returned directly to you without being logged or retained on our systems.
Encryption everywhere
All data in transit is protected with TLS 1.3. Data at rest is encrypted using AES-256. We rely on hardened key management practices from our cloud infrastructure providers.
Least-privilege access
We enforce role-based access controls, multi-factor authentication, and the principle of least privilege across all production systems and internal tools.
Continuous monitoring
Our infrastructure is monitored around the clock for anomalies, vulnerabilities, and security events. We run automated dependency scanning and respond to alerts with documented runbooks.
Cloud-native resilience
We run on leading cloud providers with network segmentation, DDoS protection, private networking, and redundant backups to keep services available and isolated.
Compliance aligned
Our controls are built around SOC 2 and ISO 27001 best practices, with continuous monitoring and third-party audit validation through Vanta. See our Trust Center for the latest status on all frameworks.
Certifications & compliance
Trust Center
We partner with Vanta to continuously monitor our security and compliance posture and share a transparent view of our controls with customers and prospects.
This security commitment is subject to change. Please review this page periodically for updates.
For security questions or to report an issue, please contact security@hicap.ai.
Please also review our Privacy Policy and Terms of Service.