Version 1.1, 2026-10-07.
Security & trust
HumanAI connects AI agents to our customers' systems. That only works if customers know who does what, under which identity, and where the data stays.
Each person in their own environment. Every user works in an isolated environment that keeps working with the laptop closed; projects of different customers are separated.
Your identity, never borrowed. Each person uses their own access tokens to customer systems, kept in their own vault. No shared accounts. What an agent does is logged in the customer's system under the name of the person who asked for it. Automatic scanning looks for secrets pasted into files.
A person decides. Agents propose; a person approves. Production changes need approval from someone with the authority, and whoever launched an operation cannot approve it alone. Sensitive platform operations require a second factor.
Data in Europe. Servers are in the EU (Germany), encrypted backups in Portugal and the portal database in Ireland. When a provider is outside the EEA, we name it and the safeguard on the subprocessors page.
Customer data stays with the customer wherever possible. From customers' data platforms we bring metadata (names, structures, definitions) and aggregates, not data rows. When an AI agent needs content to work, that content goes to the provider the customer authorised, and we say so openly.
Everything that matters is logged. Approvals, administrative access and configuration changes are kept in an audit log.
Backups. The database has continuous archiving (restore to within about a minute before an incident) plus daily copies; platform files get a daily encrypted backup (AES-256). Copies are also kept on a second company server, outside the main hosting provider, in Portugal. Encrypted off-site backups are kept for up to 6 months (7 daily, 4 weekly, 6 monthly) and then deleted in rotation. Restores are tested automatically: a sample of the encrypted backup every day, members' files every week, and a full database point-in-time restore in a separate environment every month.
Encryption at rest. Off-site backups are encrypted. Each person's workstation disk has full-disk encryption (LUKS2) since 7 October 2026: the key is requested at boot from a server of ours, and without it only a recovery passphrase kept off the machine can open the disk. The main server, which runs the platform database, does not yet have full-disk encryption; the move to an encrypted server is planned for 10 October 2026. Until then, access to it is limited to administrators over a private network. The portal database, at our database provider, is encrypted at rest by that provider.
Incidents. If an incident affects customer data, we tell the customer without undue delay and at most 48 hours after becoming aware, with the information available. Where the data belongs to accounts we manage as controller, we notify the Portuguese authority within 72 hours and the people affected when there is a high risk.
Found a flaw? See Report a vulnerability.
Contact: rpad@rpad.pt