Security

Last updated:

BG Image

Introduction

Security is built around a simple principle: Hatch’d should only have the access and authority it needs to do the work you hired it to do.

Hatch’d is not self-serve. We work directly with each customer, and security, data access and processing requirements are agreed as part of the customer relationship.

Customer control

Your team defines how Hatch’d works with your sales process.

Access to customer systems is configured for the agreed use case, and customer-specific requirements can be documented in the applicable agreement.

Where a workflow requires human approval, Hatch’d keeps that approval step in place before the action is taken.

Data protection

We design Hatch’d to limit access to customer data to what is needed to provide the service.

Customer-specific requirements covering data processing, access, retention, deletion and other security commitments are handled through our customer agreements and, where applicable, a Data Processing Addendum.

We do not sell Customer Data.

AI governance

Hatch’d uses AI to perform business research, organize information, build context and support sales workflows.

We design those systems around defined customer rules and permissions.

Hatch’d is not intended to make high-impact decisions about employment, credit, healthcare, insurance, housing or similar decisions about individuals.

AI-generated research may contain errors, and workflows can include human review where appropriate.

Third-party providers

Hatch’d may use carefully selected infrastructure, software and AI providers to operate the service.

Where those providers process Customer Data on our behalf, their role is addressed through our vendor and contractual arrangements.

Customer-specific information about relevant providers and data flows can be addressed during contracting and security review.

Security reviews

Because every Hatch’d customer has a contract with us, security requirements can be reviewed before access is granted.

Where appropriate, we can document customer-specific requirements relating to:

  • system access;

  • data processing;

  • subprocessors;

  • retention and deletion;

  • confidentiality;

  • incident handling; and

  • AI use.

Compliance

Hatch’d does not currently claim SOC 2 or ISO 27001 certification.

We would rather be clear about the controls we have than claim certifications we have not earned.

Our security and AI risk-management practices are developed with established frameworks such as the NIST Cybersecurity Framework and NIST AI Risk Management Framework as reference points.

Use of these frameworks does not mean Hatch’d is certified or independently audited against them.

Report a security issue

If you believe you have found a security or privacy issue involving Hatch’d, please contact us.

Hatch’d
Numerra Technology, Ltd
Solvagen 20
724 60 Vasteras
Sweden

hello@gethatchd.com