Security

Your data is in safe hands.

Client work is someone else's confidential material. We host it where you choose, and we never train on it. Access stays with the people your firm has already allowed.

In practice

Where it lives, who can see it, and what we do not do with it.

Data residency you choose

Platform storage is in the EU or the US, whichever you picked when the workspace was created. Inference runs where that model provider runs: the US for OpenAI, Anthropic, and xAI; China for DeepSeek. Enable only EU-resident providers if the work has to stay in the EU.

No training on your data

Hebno does not use your inputs or outputs to train any model. Providers process inference under their own terms, for the models you have switched on.

Encrypted end to end

AES-256 at rest, TLS 1.2 or higher in transit. If you supply your own provider API keys, those are encrypted at rest too.

Access control and audit

Owner, admin, and member roles. Connected sources keep the permissions those accounts already have. We record sign-in, admin changes, and usage.

The work you put in

Follow a piece of work through Hebno.

It stays in your organisation's workspace. We send it over a direct API connection to the model you enabled, the reply comes back for review, and we do not use it to train a model. Usage is recorded against the person, team, and client on the conversation.

A prompt

Written in your workspace

Stored with the conversation, not mixed with anyone else.

Sent to the model you enabled

A direct API call. Nothing else is in that request.

Draft comes back for review

The reply returns with sources attached.

Not used to train a model

A connected source stays in that system, including custom connectors your firm sets up. Hebno can search it, or you can pick a file, using the permissions the account already has. What is used in the conversation is stored there. Someone who cannot open the file in the source system does not get it by asking an assistant.

Connected sources

  • Board pack.pptx
  • Q3 client brief.docx
  • Internal notes.md
  • Budget FY26.xlsx

Searched with your permissions

In this chat

Q3 client brief.docx

Brought in for this chat. The rest stays in the source.

Files you drag into chat go to your organisation's private storage, encrypted at rest. They stay on the conversation so the history still makes sense. They follow the same deletion terms as the rest of your workspace data.

An upload

Interview notes.pdf

Dragged into this chat

  • Private organisation storage, encrypted at rest.
  • AES-256 on the file. TLS 1.2 or higher on the way in.
  • Stays on this conversation so the history still makes sense.

The reply (a draft, an email, a note) is stored on that conversation in your organisation's workspace. We do not use it to train a model. It stays there until someone on your team copies or sends it, or the conversation is deleted. Then it follows the same deletion terms as the rest of the workspace.

An output

Client update

For review

Subject: Q3 progress

Sharing a first cut of the findings from the brief you sent through. Sources are attached in the thread. Please review before this goes to the client.

  • Stored on this conversation in your workspace.
  • Leaves Hebno only if someone on your team copies or sends it.
  • Not used to train a model.

Questions a client might ask

People who work on the platform are bound by confidentiality. Access for support is limited to what is needed to fix a problem. We do not browse customer work as a matter of course.

You can export data using product features. We delete customer personal data within 30 days of termination unless the law requires us to keep it. Backup copies may persist for up to 90 days before they are overwritten.

Yes. Accepting the terms incorporates the online DPA for business use. Enterprise customers can request a signed version with custom annexes. Write to support@hebno.com.

Email support@hebno.com. If we confirm a personal data breach that affects your data, we notify you without undue delay, and within 72 hours where feasible.

Bring your security questions to a demo.

Book 20 minutes. You will watch a team go from brief to source-backed draft, with every source visible and ready for delivery.