Skip to content
Hendl
TRUST  /  SECURITY/ built for regulated casework

Your cases carry people's lives. We build like it.

Hendl holds claims, complaints and investigations — some of the most sensitive data an organisation handles. Security isn't a page on our website; this is simply where we write down how the platform works.

§
GDPR & DPA 2018
DPA with every contract
UK & EU residency
Stored and processed in-region
Tenant isolation
Separate storage and keys
No training on your data
Contractual, never
PLATFORM

Isolated by default. Encrypted everywhere.

Every customer runs in an isolated tenant, in the region you choose, encrypted in transit and at rest — with your data never used to train shared models.

Tenant isolation

Every customer in an isolated tenant — separate storage, keys and processing.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest, keys managed and rotated per tenant.

UK & EU residency

Choose where your data lives; it is processed and stored in-region.

No training on your data

Your data is never used to train shared models. Ever. Contractually.

SSO & SCIM

SAML and OIDC single sign-on, SCIM provisioning, enforced MFA.

Role-based access

Permissions by role, team and case — least privilege by default.

Immutable audit log

Every access and action logged, tamper-evident and exportable.

Resilience

Multi-zone infrastructure, continuous backups, tested recovery.

AGENTS

Autonomy needs harder guarantees.

Agents that act on cases raise questions a normal SaaS security page never has to answer. Here's how we answer them.

01
Governed tools only

Agents touch your systems through permissioned tools — each grants specific actions on specific systems, nothing more.

02
Approval gates

Payments, settlements and external messages always stop for a named person. Autonomy is configured per agent, per action.

03
Least-privilege agents

An agent sees only the cases and data its task requires — the same access model as people.

04
Full provenance

Every agent action records its trigger, inputs, tool calls and sources — replayable end to end.

05
Kill switch

Pause one agent, one case, or everything — instantly, with running work halted safely.

YOUR DATA

Yours on the way in. Yours on the way out.

01
Intake

Data enters through encrypted channels and is hashed, classified and logged on arrival.

02
In use

Processed inside your tenant only, under case-level access controls and full audit.

03
Retention

Kept to your retention schedule per case type — then deleted, verifiably.

04
Exit

Full export in open formats at any time. Leaving is easy; that keeps us honest.

PRACTICE

Security as an operating habit.

Continuous testing

Continuous automated scanning across the platform, with findings triaged and tracked to closure.

Change control

Peer-reviewed changes, staged rollouts and audit-logged deployments.

Vetted personnel

Background checks, security training and least-privilege access for all staff.

Incident response

A tested plan with defined notification windows — you hear from us fast.

Vendor scrutiny

Subprocessors reviewed and listed; changes notified in advance.

§
Contractual teeth

DPAs, SLAs and audit rights in the contract, not on request.

Found something?
We run a responsible disclosure programme and respond within one business day — security@hendl.ai.
Disclosure policy →

Questions security teams ask.

Which AI models run the platform, and where?

Hendl runs on frontier models via enterprise agreements with zero-retention terms. Prompts and outputs stay in your tenant’s region and are never used to train shared models.

Can we bring our own keys?

Yes — enterprise deployments support customer-managed keys, with rotation and revocation under your control.

How do you handle subject access and deletion requests?

Per-case data maps make SARs and erasure practical: locate, export or verifiably delete a person’s data across cases, with the actions themselves logged.

Will you complete our security questionnaire?

Yes. We maintain completed SIG and CAIQ assessments, and our security team works your process directly — questionnaires, calls and evidence requests.

What happens if an agent misbehaves?

Its permissions bound the blast radius, gates stop consequential actions, provenance shows exactly what happened, and the kill switch stops it immediately.

Can we audit you?

Enterprise contracts include audit rights. You also get the security pack, the DPA and the subprocessor list as standard.

Put us through your security review. We'll keep pace.

Full documentation, completed vendor assessments and direct access to our security team — from the first call.

© 2026 Hendl Labs Ltd. All rights reserved.
Services AgreementPrivacy PolicyTrust Center