No Hallucination Guarantee now liveLearn more

Security Controls

Last updated: Sept. 4, 2026

At Hudson Labs, security and confidentiality are foundational to how we build the Co-Analyst. Our platform is designed to meet the requirements of institutional investors, research teams, and enterprise customers who depend on strict data protection and operational controls.

At a glance

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • MFA enforced on all data platforms used; passwords salted and hashed
  • Role-based access controls, least-privilege access, recurring access reviews, and audit logs
  • We do not train AI models on customer data
  • Continuous vulnerability scanning with risk-based remediation timelines
  • Annual independent penetration testing (most recent: September 2026)
  • No known client data breaches to date

AI, Privacy & Customer Data

Hudson Labs is built so you can use the Co-Analyst on your most sensitive research tasks with confidence.

No Training on Customer Data: User data, prompts, and search activity are never used to train AI or machine learning models. Customer data is not shared with external model providers for training purposes.

Strict Data Isolation: Each customer's data is logically isolated within our platform. Access controls and system boundaries are designed to prevent any cross-customer access or data leakage.

Secure Model Execution: Model inference environments are fully isolated, preventing data exfiltration. When third-party AI models are used to process a request, only the content of the query is transmitted — no account, profile, or identifying data is shared with model providers.

Prompt Storage Controls: Client data and prompts are encrypted and stored in a secure internal database. Users may opt out of prompt storage at any time, with potential limitations to certain functionality, such as saved workflows and prompt reuse.

Uploaded Documents: Documents that a customer uploads are encrypted at rest using AES-256 and in transit, are covered by the same per-customer data isolation as all other customer data, and are never used to train AI or machine learning models. Uploaded content is used only to provide the Co-Analyst to that customer. When a request requires a third-party model, only the content necessary to process the request is transmitted. Uploaded documents are processed within the Hudson Labs environment and on AWS and Azure cloud infrastructure.

AI Guardrails: Hudson Labs implements AI safety and content guardrails using third-party tools, including Guardrails AI and NVIDIA NeMo. These systems are designed to mitigate risks related to bias, toxicity, and inappropriate content.

Model Monitoring: Drift and regression testing is performed at least quarterly and typically more frequently — approximately every three weeks. Both automated and manual evaluation methods are used, and the regression test suite is continuously updated.

Infrastructure Security

Built on AWS: Hudson Labs is hosted on Amazon Web Services and Microsoft Azure in US- and Canada-based regions, leveraging their secure, globally trusted cloud infrastructure. We use AWS and Azure security primitives for network isolation, access control, and infrastructure protection.

Encryption by Default: All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. This protects customer data both while it is being transmitted and while it is stored in our systems.

Authentication: Multi-factor authentication is enforced internally across all data platforms used. Passwords are salted and hashed using industry-standard methods.

Internal Access Controls: Access to production systems and customer data is restricted to authorized Hudson Labs personnel on a least-privilege basis. Role-based access controls are enforced internally, ensuring staff can access only the systems and data necessary for their roles. Access is formally provisioned and removed, administrative access is limited, and access rights are reviewed regularly, including after role changes. Access for departing personnel is revoked within 24 hours or one business day.

Monitoring & Logging: Production systems are monitored continuously using health checks and critical-error alerts. Network and system access is logged and reviewed for unauthorized activity, and logs are protected from tampering. Audit trails are maintained for key system, administrative, and production-change actions.

Endpoint & Remote-Work Security: Hudson Labs provides company-managed work devices. Full-disk encryption and anti-malware or equivalent endpoint monitoring are required, security patches must be installed promptly, and mobile devices may not connect directly to production environments. Lost or stolen devices must be reported immediately so access can be deactivated.

Secure Development Practices: Hudson Labs follows a secure software development lifecycle. Development, testing, staging, and production environments are separated; code changes are reviewed and tested before deployment; and secrets are kept out of source-code repositories. Static and dynamic application security testing, dependency scanning, and container and infrastructure-as-code scanning are incorporated into the development and deployment process. High and critical security issues identified before release must be resolved before deployment.

Controlled Changes: Production changes follow a documented, risk-based process that includes review, approval, testing in a non-production environment, implementation by authorized personnel, and a rollback plan. Changes are logged, and significant changes receive a post-implementation review.

Vulnerability Management: Hudson Labs continuously monitors production systems and uses static analysis, dependency management, and independent penetration testing to identify vulnerabilities. Remediation is prioritized by severity, with target timelines of seven days for critical issues, 30 days for high-severity issues, and 90 days for medium-severity issues. Any exception must be documented, approved, and supported by compensating controls.

Regular Penetration Testing: Hudson Labs engages independent security experts to conduct penetration testing every six months. The most recent test was performed in September 2026. Findings are remediated on a risk-prioritized basis, and results are available to enterprise customers on request under NDA.

Enterprise Controls & Data Lifecycle

User Access Controls: Hudson Labs manages access through user tiers and permission levels that determine what each user can see and do within the platform. Access configuration is handled in coordination with Hudson Labs. Contact your account representative to adjust user permissions or tiers.

Upload Access Controls: Uploaded documents are treated as confidential customer data and are encrypted at rest and in motion, protected by role-based, least-privilege access controls. Access is confined to the customer's own environment and is never available across customers. Enterprise administrators can opt their team in or out of shared access to uploads, and access to uploaded content is captured in audit logs.

Data Classification & Minimization: Hudson Labs classifies information according to its sensitivity and applies corresponding handling, access, encryption, and disposal controls. Customer data is classified as confidential. Hudson Labs maintains data inventories and data-flow records and limits collection and retention to information needed for a defined business, contractual, or legal purpose.

Data Retention & Deletion: Data is retained only as long as needed for the purpose for which it was collected or to satisfy legal, regulatory, or contractual obligations. Usage data and history are automatically deleted one year after either the end of the contractual term or the last account login. Clients may request access to, correction of, or deletion of their data as required by applicable law, subject to legal holds and other retention requirements. A customer may delete an uploaded document at any time. Uploaded documents are deleted within 24 hours of deletion of the user account. Residual encrypted backup copies are retained for no more than one year and are then securely deleted or overwritten through the normal backup lifecycle.

Data Residency: Customer data is stored on AWS infrastructure in US- and Canada-based regions. If data residency is a specific requirement for your organization, please contact us to discuss your needs.

Controlled Sharing & Export: Hudson Labs provides controls around sharing and exporting data to help prevent accidental or unauthorized data exposure.

Third-Party Providers: All vendors require leadership approval before onboarding. Any third-party technology solution that will connect to the production environment undergoes a documented vendor risk review, including review of relevant security documentation and data-segregation and deletion controls. Hudson Labs reviews its vendor inventory annually, and production systems are hosted only with cloud providers that maintain SOC 2 or equivalent security certifications. Additional contractual protections, including data processing agreements, are put in place where required.

Sub-ProcessorLocationPurpose
Amazon Web Services (AWS)United States and CanadaCloud infrastructure and data storage
AmplitudeUnited StatesProduct analytics
StripeUnited StatesPayment processing
Customer.ioUnited StatesMarketing communications
Copper CRMUnited StatesCustomer relationship management
Microsoft AzureUnited States and CanadaCloud infrastructure and data storage
Heroku PostgresUnited StatesData storage
Google WorkspaceUnited StatesData storage and email
OpenAIUnited StatesQuery processing and analysis
TurbopufferCanadaData storage

IP, Data & Licensing

Data Sources: Hudson Labs sources data from licensed providers and public sources. Key sources include S&P Global Market Intelligence, SEC.API, and publicly available SEC filings through EDGAR. Data is ingested through controlled API or SFTP processes. Additional details on data coverage and content sources are available in the Hudson Labs FAQ.

MNPI Policy: Hudson Labs maintains a formal Data, MNPI, and PII Policy. MNPI risk assessments are conducted for all new data vendors. All data sources used in the platform are publicly available and widely disseminated, resulting in minimal MNPI risk. Details are available in Section XII.02 of our Terms of Service.

Training Corpus: Hudson Labs' AI models are trained on publicly available SEC filings obtained through EDGAR and used in accordance with applicable terms and regulations.

IP & Indemnification: Hudson Labs complies with all applicable intellectual property requirements. Details on IP indemnification are provided in Section VIII.02 of our Terms of Service.

Compliance, Risk & Governance

Security Framework: Hudson Labs aligns its security controls with SOC 2 standards across security, availability, and confidentiality.

Privacy & Data Protection: The full Hudson Labs Privacy Policy is available on our website.

Security Policies & Governance: Hudson Labs operates under formal internal policies covering acceptable use, access and password management, asset and data management, secure development, change and vulnerability management, vendor risk, incident response, and business continuity. All staff and contractors sign a Code of Ethics committing to integrity and confidentiality, reaffirmed at least every two years, and complete annual cybersecurity training. Software development personnel also complete secure-coding training annually.

Risk Management: Information-security risks are recorded in a risk register, assigned an owner, assessed by likelihood and impact, and addressed through documented mitigation, avoidance, transfer, or acceptance decisions. Control effectiveness is reviewed at least annually, and high residual risks require priority treatment or exceptional approval by senior management.

Privacy & Security Officer: Hudson Labs' Privacy and Security Officer is Suhas Pai, a former Staff Software Engineer at IBM Security with five years of experience in identity and access management, cryptography, and vulnerability detection. Suhas co-led the Privacy Working Group for the BigScience BLOOM LLM and is a co-founder of PIISA, the Personally Identifiable Information Standard Architecture.

Reliability & Incident Response

Reliability & Backups: Hudson Labs operates on resilient cloud infrastructure with regular database backups and continuous monitoring to support platform availability and data integrity. Backup and recovery systems are protected to the same standard as primary systems, and recovery procedures for critical systems are tested at least annually.

Incident Response: Hudson Labs maintains a formal incident response process to detect, validate, contain, eradicate, and recover from security incidents. The process is reviewed at least annually and after major events, and resolved incidents receive a documented postmortem so lessons learned can be incorporated into controls and procedures. Clients are notified of any material data breach without undue delay and no later than 24 hours after discovery. Hudson Labs has not experienced any known client data breaches to date.

Business Continuity: Hudson Labs maintains business continuity and disaster recovery plans for critical functions and systems. Recovery Time Objectives and Recovery Point Objectives are established through business impact analysis, and plans are reviewed at least annually and after significant operational changes or disruptions.

Responsible Disclosure

We welcome responsible disclosure from the security community. If you believe you have discovered a security issue, please contact security@hudson-labs.com. We aim to acknowledge all reports within five business days and will keep you informed as we investigate and address the issue.