Your cases carry people's lives. We build like it.
Hendl holds claims, complaints and investigations — some of the most sensitive data an organisation handles. Security isn't a page on our website; this is simply where we write down how the platform works.
Isolated by default. Encrypted everywhere.
Every customer runs in an isolated tenant, in the region you choose, encrypted in transit and at rest — with your data never used to train shared models.
Every customer in an isolated tenant — separate storage, keys and processing.
TLS 1.2+ in transit, AES-256 at rest, keys managed and rotated per tenant.
Choose where your data lives; it is processed and stored in-region.
Your data is never used to train shared models. Ever. Contractually.
SAML and OIDC single sign-on, SCIM provisioning, enforced MFA.
Permissions by role, team and case — least privilege by default.
Every access and action logged, tamper-evident and exportable.
Multi-zone infrastructure, continuous backups, tested recovery.
Autonomy needs harder guarantees.
Agents that act on cases raise questions a normal SaaS security page never has to answer. Here's how we answer them.
Agents touch your systems through permissioned tools — each grants specific actions on specific systems, nothing more.
Payments, settlements and external messages always stop for a named person. Autonomy is configured per agent, per action.
An agent sees only the cases and data its task requires — the same access model as people.
Every agent action records its trigger, inputs, tool calls and sources — replayable end to end.
Pause one agent, one case, or everything — instantly, with running work halted safely.
Yours on the way in. Yours on the way out.
Data enters through encrypted channels and is hashed, classified and logged on arrival.
Processed inside your tenant only, under case-level access controls and full audit.
Kept to your retention schedule per case type — then deleted, verifiably.
Full export in open formats at any time. Leaving is easy; that keeps us honest.
Security as an operating habit.
Continuous automated scanning across the platform, with findings triaged and tracked to closure.
Peer-reviewed changes, staged rollouts and audit-logged deployments.
Background checks, security training and least-privilege access for all staff.
A tested plan with defined notification windows — you hear from us fast.
Subprocessors reviewed and listed; changes notified in advance.
DPAs, SLAs and audit rights in the contract, not on request.
Questions security teams ask.
Which AI models run the platform, and where?
Hendl runs on frontier models via enterprise agreements with zero-retention terms. Prompts and outputs stay in your tenant’s region and are never used to train shared models.
Can we bring our own keys?
Yes — enterprise deployments support customer-managed keys, with rotation and revocation under your control.
How do you handle subject access and deletion requests?
Per-case data maps make SARs and erasure practical: locate, export or verifiably delete a person’s data across cases, with the actions themselves logged.
Will you complete our security questionnaire?
Yes. We maintain completed SIG and CAIQ assessments, and our security team works your process directly — questionnaires, calls and evidence requests.
What happens if an agent misbehaves?
Its permissions bound the blast radius, gates stop consequential actions, provenance shows exactly what happened, and the kill switch stops it immediately.
Can we audit you?
Enterprise contracts include audit rights. You also get the security pack, the DPA and the subprocessor list as standard.
Put us through your security review. We'll keep pace.
Full documentation, completed vendor assessments and direct access to our security team — from the first call.