Security Policy

Last updated: July 19, 2026

This Security Policy describes the administrative, technical, and organizational measures HexaHQ (Salesbot Labs, Inc., doing business as HexaHQ) uses to protect customer data. It is the Security Policy referenced by our Terms of Service and Data Processing Agreement. We update it as our practices evolve; security is a continuous program, not a fixed checklist.

Security and governance built into every action

HexaHQ is a governed action layer between an organization's AI clients and its connected business systems. Security is not a separate feature; it is how HexaHQ works. Every action an AI takes through HexaHQ passes an organization-configured allow / ask / deny approval policy: reads can be allowed to run, while actions that write, send, or delete can require a person to approve them first. Every action is recorded on an audit timeline that captures who acted, what changed, on whose approval, and when. Each person acts under their own identity, so attribution is preserved even when a connection is shared across a team.

Credential custody

Provider credentials (API keys, OAuth tokens, and connected-service secrets) are entered out-of-band in the browser and stored server-side; they are never entered, relayed, or displayed in the AI chat, and they are not placed in customer code. Credentials are encrypted at rest, and all provider access is brokered through a single internal resolution path so that access is consistent, scoped, and auditable. Where a provider supports it, tokens are short-lived and refreshed automatically rather than held longer than necessary.

Encryption

Customer data is encrypted in transit using industry-standard transport encryption (HTTPS/TLS) between users, HexaHQ's systems, connected third-party services, and sub-processors. Customer data is encrypted at rest using encryption provided by our cloud infrastructure and managed data-storage services, with encryption keys managed through our cloud provider's key-management service. We require encrypted connections for production services where supported and do not intentionally transmit customer data over unencrypted public networks.

Authentication and access control

Users authenticate with an email address and password or through a supported identity provider such as Google. Passwords are subject to minimum-strength requirements, stored using secure one-way hashing, and never stored in plaintext. When users authenticate through an identity provider, authentication is subject to the controls configured for that account, which may include multi-factor authentication. Access to customer accounts and connected applications is governed by assigned roles, permissions, and the organization's approval policy. Administrative access to production systems is limited to authorized personnel on a least-privilege basis, granted only as needed to operate and support the service.

Logging, monitoring, and audit

We maintain event logging and audit records to support security monitoring, troubleshooting, and incident response. Logged events include infrastructure and administrative activity, configuration changes, network activity, application and deployment logs, and product-level records of workflow execution and authorization decisions. Logs are stored in managed logging and storage services with access controls, encryption, defined retention, and integrity protections. We use automated monitoring and alerting to identify suspicious activity and material changes to our environment.

Infrastructure and resilience

HexaHQ runs on Amazon Web Services. Production infrastructure is provisioned and maintained as version-controlled infrastructure-as-code, with changes reviewed before deployment and applied through controlled processes. Edge and network protections guard the application perimeter. We use managed cloud infrastructure with backup, redundancy, and recovery capabilities designed to restore availability of and access to customer data following accidental loss, corruption, or a physical or technical incident, and we maintain documented recovery procedures.

Secure development and change management

We manage application and infrastructure configuration through version control. Changes are reviewed before they reach production and applied through controlled deployment processes. We use secure default configurations where available, apply updates and patches as appropriate, and manage third-party dependencies as part of ordinary maintenance. Security-relevant configuration and controls are reviewed and updated based on operational and security needs.

Data segregation, retention, and deletion

Customer data is logically segregated between customer accounts. We limit collection and processing to data a customer submits, connects, or makes available and to what is reasonably necessary to provide, secure, support, and operate the service; customers control which knowledge, applications, permissions, and data sources are connected. We retain customer data only as long as reasonably necessary to provide the service and to meet legal obligations. On termination or expiration, we delete or return customer data in accordance with the applicable agreement and customer instructions, subject to limited retention in backups and records required by law; data retained in backups is protected from ordinary use and expires through our standard backup lifecycle.

Sub-processors

We keep our list of sub-processors short and publish it at hexahq.ai/subprocessors. The third-party providers you connect through HexaHQ (your CRM, email, calendar, and other applications) and the AI client you use act on your instruction under their own terms and are not HexaHQ sub-processors; you control which are connected and can disconnect any of them at any time.

Incident response

We maintain documented incident-response procedures. Security events are assessed and escalated according to their severity, with designated personnel responsible for investigation, containment, remediation, and recovery. Where an incident affecting customer personal data requires it, we notify affected customers in accordance with our Data Processing Agreement and applicable law.

Privacy and compliance

Our handling of personal data is described in our Privacy Policy and governed, for business customers, by our Data Processing Agreement, which offers GDPR and UK GDPR terms (including Standard Contractual Clauses for international transfers) and addresses our role as a service provider under the CCPA/CPRA. We do not sell customer data, and we do not use customer data to train generalized AI or machine-learning models.

Reporting a security concern

To report a security concern or request additional information about our security practices, contact support@hexahq.ai. For privacy questions or data-subject requests, see hexahq.ai/privacy-request.