Privacy centre

Optional technologies stay off unless you enable them. You can return here from the footer and change your choice at any time.

Necessary

Required for security, form protection, and remembering your privacy choice.

Always on

Analytics

Google Analytics and Microsoft Clarity help us understand site use and improve usability.

Marketing

Google Ads, Meta, LinkedIn, HubSpot, Apollo, and RB2B help measure campaigns and understand business interest.

Cloudflare Web Analytics remains active because it is cookieless, does not use local storage, and does not collect or use visitors' personal data. See full details.

Every action controlled. Every decision explainable. Every write reversible.

HachiAI's Intelligent Digital Workers run under enterprise-grade governance, built in from day one, not bolted on after. Every action goes through scoped access and policy checks, high-risk writes wait for a human approval, every step lands in an immutable audit trail, and any write rolls back in one click. Deployed wherever your compliance requires: our cloud, your private cloud, hybrid, or on-prem.

ISO 27001 & ISO 42001 certified · GDPR & PIPEDA compliant · SOX, HIPAA, and SOC 2 Type II deployment paths on request.
100%Actions audit-trailed
HITLOn high-impact writes
1-clickRollback with full trail
4Deployment models

What do these certifications actually prove?

Three external standards back the controls above. ISO 27001 and ISO 42001 are verified by accredited third-party auditors, not self-declared. Here is what each one covers, and why it matters for you.

ISO/IEC 27001

Information security, certified

The international standard for information security management. An accredited, independent auditor verifies that we have the controls, processes, and continual monitoring needed to protect the confidentiality, integrity, and availability of your data.

For you: your operational data is protected by audited security controls, not just our assurances.

Responsible AI, certified

ISO/IEC 42001:2023 is the first international standard for AI management systems. It defines how an organization governs the AI it builds and operates: risk management, transparency, human oversight, bias and data quality, and continual improvement. It is new and demanding, and few AI vendors hold it yet.

For you: proof our AI is run under an audited governance framework, not deployed ad hoc, the assurance a board and risk team need before AI touches production.

GDPR

Data privacy, compliant

The EU General Data Protection Regulation governs how personal data is collected, processed, and stored. We handle data lawfully and transparently, with data minimization, purpose limitation, and respect for individuals' rights, including access and erasure.

For you: personal and customer data in your workflows is handled to a recognized global privacy bar, and is never used to train public models.

Controlled, explainable, reversible by design.

Controlled · Every action

IDWs act only through pre-approved tools and scoped credentials, with policy and risk checks on every step.

Explainable · Every decision

Each decision carries its reasoning and a confidence score, so you can see why an action was taken, not just that it was.

Reversible · Every write

High-impact writes pass through human approval, and any action can be rolled back in one click with a full audit trail.

Enterprise-grade governance, built in from day one.

Eight controls wrap every Intelligent Digital Worker, so autonomy never comes at the cost of oversight.

Eight controls Active

Tool allowlists & scoped credentials

Only pre-approved tools can execute writes, each with least-privilege, scoped access.

Run it wherever your compliance requires.

From fully managed cloud to fully local, the same governance applies in every model.

Cloud
Same governance
Scoped access
Audit trail

Your data stays private and secure.

Security controls · Enterprise-compliant by design.

  • Identity management and access control
  • Data governance and model isolation
  • Encrypted credentials at rest and in transit
  • Local model support for sensitive processing
  • SOX, HIPAA, and SOC 2 Type II deployment paths available on request

Data security & privacy · Your operational data stays yours.

  • Sensitive data stored locally in self-hosted deployments
  • Task artifacts remain within designated local directories
  • Credentials encrypted at rest, used only for approved actions
  • Your data is never used to train public models

Certified and compliant to the frameworks your auditors expect.

Independently certified, with deployment paths for the frameworks your auditors expect.

ISO 27001 Certified
ISO 42001 Certified
GDPR & PIPEDA Compliant
SOX path
HIPAA path
SOC 2 Type II path

Governance questions leaders ask us.

How is the work governed?

IDWs never operate unchecked: scoped credentials, policy-based approval thresholds, human review on high-risk writes, immutable before-and-after audit trails, low-confidence escalation, and rollback where an action is reversible, with defined remediation and escalation where it is not. Every action is controlled and reviewable.

Is our data secure? Can it run on-premise?

Yes. Your data stays private and is never used to train public models. HachiAI is ISO 27001 and ISO 42001 certified and GDPR and PIPEDA compliant, and IDWs deploy in our cloud, your private cloud, or fully on-premise for regulated environments.

Governance you can take to your board.

See exactly how these controls apply to your workflows, systems, and compliance requirements. Built and run by operators who have carried this work through audits in production.