SECURITY
Security posture
What we do today, what we explicitly do not claim, and how to report a vulnerability. Written for the security reviewer who reads this in 90 seconds.
- Report to
- security@huitzo.com
- Disclosure window
- 90 days
Section 1: THE BOUNDARY
Security
Your data never leaves your environment. Not in transit, not in processing, not in logs.
The licensed runtime and its Intelligence Packs run inside infrastructure you control. Packs never phone home, and every run produces an audit record inside that environment.
Huitzo is a self-hosted AI runtime for regulated organizations: the runtime and every Intelligence Pack it hosts run inside the customer's own network boundary, not a vendor cloud like AWS Bedrock or Azure AI. Huitzo Hub is a separate hosted evaluation surface and is not the data boundary described here. Most licensed deployments go live in weeks, not the 12-18 months a custom build typically requires. This page is the running statement of what we do today, what we do not claim, and how to report a vulnerability.
FIG. 01. WHERE THE RUNTIME LIVES.
Section 2: WHAT WE DO TODAY
What security controls does Huitzo have in place today?
02.1
Developer tooling and the interactive quickstart (build-with-huitzo) are public at github.com/huitzo-inc. Runtime source review is available on request.
02.2
Customer deploys the runtime inside infrastructure they control.
02.3
The self-hosted runtime sends nothing to Huitzo, and that includes logs. Packs never phone home; it is enforced by architecture, not policy.
02.4
Audit records are written inside the deployment and stay there. Huitzo has no copy.
02.5
The customer chooses the model. A self-hosted model keeps every prompt inside the network; a hosted provider receives only declared prompts, and the audit record states what crossed.
02.6
All inter-component traffic inside a deployment is over TLS by default.
02.7
Secrets are sourced from the host environment; Huitzo does not bundle a secret store.
Developer tooling and the interactive quickstart live at github.com/huitzo-inc.
Section 3: WHAT WE DO NOT CLAIM
Is Huitzo SOC 2 or HIPAA certified?
No. Stated plainly, here is what we do not claim today. If any item below changes, it moves to the controls list above the same week as the certification or third-party audit lands.
03.1
Not SOC 2 Type I or Type II audited.
03.2
Not ISO 27001 audited.
03.3
No published uptime SLA. Self-hosted runtime; uptime is a property of the customer's deployment.
03.4
Not independently penetration-tested.
03.5
Not HIPAA-, PCI-DSS-, FedRAMP-, or GDPR-certified. The runtime can be operated inside a customer's compliant environment, but Huitzo does not certify the customer's environment.
Section 4: DISCLOSURE
Vulnerability disclosure
- Report to
- security@huitzo.com
- Disclosure window
- Standard 90-day disclosure window.
- Bug bounty
- Huitzo does not run a paid bug bounty program.
Section 5: QUESTIONS
Security questions
Is Huitzo SOC 2 compliant?
Does Huitzo store my data?
Does Huitzo collect telemetry, usage data, or logs from my deployment?
Which AI models can I use, and does my data go to them?
Is Huitzo HIPAA compliant?
What is your uptime SLA?
Has Huitzo been penetration-tested?
How do I report a security vulnerability?
Section 6: CLOSING
AI operating system for regulated companies
Simple by design. Built to scale. Runs where your data lives.
- Product access
- Huitzo Hub is available by invitation for teams evaluating the product.