SECURITY

Heplon connects to your live platform, so where your data lives and what our agents can touch matters. Here is how both work.

WHERE YOUR DATA LIVES

Data from your connected systems is processed by Heplon. You choose where that happens.

DEFAULT

Managed hosting

  • Heplon runs in our AWS infrastructure.
  • For systems that are not reachable over the public internet, you deploy a small agent inside your network. It opens a TLS-encrypted connection to Heplon and runs queries against the internal systems you connect to Heplon.
  • The agent needs no inbound access from the internet.
  • We run, scale, patch, and monitor everything, following AWS security best practices.
  • Your workloads are isolated from other customers, and your data is encrypted in transit and at rest.
OPTIONAL

Bring your own cloud (BYOC)

  • You give us access to a cloud account under your control, and we deploy Heplon into it as a dedicated, single-tenant environment.
  • Your data never leaves infrastructure you own and control.
  • We still run it for you. We manage updates, monitoring, and fixes remotely.
  • A good fit if you have strong data residency, sovereignty, or compliance requirements.

DATA HANDLING

Your code

  • To power Heplon, we build and store a knowledge graph derived from your repositories: a structural map of your components and how they interact. It lives in the same cloud environment as the rest of your deployment.
  • The graph may include identifiers and signatures from your code, but not full source files.

Logs and telemetry

  • We store operational logs for 90 days to run, secure, and troubleshoot the service.
  • After 90 days, logs are deleted or de-identified.
  • Like everything else, logs stay inside the same cloud environment as the rest of your deployment.

AI processing

  • Managed hosting: we run our models through managed inference providers that operate inside the EU. They are named in our data processing agreement.
  • BYOC: inference runs inside your own cloud account, alongside the rest of your deployment.

PERMISSION MODEL

Heplon never gets blanket access to your systems. Everything is scoped to roles you define, and agents inherit only what a role is allowed to see.

You define the roles.

Set up or import roles such as developer or platform engineer. For each role you choose which live systems and docs it can reach. Different roles can see different systems and authenticate in different ways.

You choose how each connection authenticates.

For every connection on a role, pick one of:

  • A dedicated service account.
  • Inherit the user’s own permissions via OAuth.

How agents use those roles

Troubleshooting

Heplon acts as the role of the user who triggered it. It can only see the knowledge and live state exposed by the connections set up for that role. The agent runs in a sandbox that holds only those credentials.

Guiding coding agents

Works exactly like troubleshooting. The agent that compiles relevant knowledge runs as the triggering user’s role, in a sandbox limited to that role’s connections and credentials.

Platform insights and improvements

You choose which of your roles power this feature. The agents that generate insights can only access what those roles can access, nothing more.

INFRASTRUCTURE AND SUBPROCESSORS

MANAGED

Two subprocessors, both in the EU.

Heplon runs entirely on AWS. Model inference runs on AWS and on a dedicated EU inference provider, both within the European Union.

Both are named in our data processing agreement. We do not hand your data to any other third-party processor.

BYOC

We add no subprocessors.

Heplon deploys into the cloud account you own and control, so your data is only ever processed within your own infrastructure, under your existing relationship with that provider.

We introduce no third-party processor of our own.

HOW WE OPERATE

Encryption

  • In transit: TLS 1.3 for data moving between clients, the service, and connected systems.
  • At rest: AES-256 encryption for stored data.

Access control

  • Access to production systems is limited to authorized personnel with a business need.
  • We apply least-privilege access and review it periodically.
  • Administrative access requires strong authentication.
  • We keep immutable audit logs of access and key actions for security analysis.

Secure development

  • Code review and change controls.
  • Dependency and vulnerability scanning.
  • Separate dev, staging, and production environments.
  • Security testing and periodic assessments.

INCIDENT RESPONSE AND RESILIENCE

Incident response

We maintain an incident response process to investigate, contain, remediate, and communicate security events.

Customer notifications

If we confirm a security incident affecting your data, we will notify you consistent with our contractual and legal obligations.

Backups and recovery

We maintain backups to support service continuity and disaster recovery. Data deleted from active systems may remain in backups until the backup retention period expires.

YOUR RESPONSIBILITIES

Security is shared. To keep your deployment safe, we ask that you:

  • Use strong authentication and enforce MFA where possible.
  • Manage access with least privilege and remove inactive accounts promptly.
  • Avoid putting secrets in any text inputs, logs, or prompts submitted to the service.

COMPLIANCE

COMPLIANT

GDPR

As a Germany-based company, we are fully GDPR compliant. Your data is handled in line with European data protection law.

IN PROGRESS

SOC 2

We are not SOC 2 certified yet. We are an early-stage team building toward formal certification, and in the meantime we follow the practices it expects: strict tenant isolation, least-privilege access, and encryption of your data in transit and at rest.

If you have a security review, questionnaire, or specific compliance requirement, we are happy to walk through it with you. Just reach out.

REPORT AN ISSUE

Found a vulnerability, or have a question about how we handle your data? Email us and we will get back to you.

security@heplon.com