Skip to content
Trust Center

Built for the people building serious AI

Our customers range from enterprise ML teams and applied-AI startups to the leading labs and hyperscalers training the most capable models in the world. This Trust Center documents the security, privacy, and contractual controls we operate so procurement teams don't have to guess.

SOC 2 Type II
Planned
ISO/IEC 27001
Planned
GDPR
In effect
CCPA / CPRA
In effect

We list certifications only when formally held. SOC 2 and ISO 27001 are aligned and on the roadmap — controls live today, audit not yet completed. See the full control inventory for detail.

How we operate

Data security

AES-256 at rest, TLS 1.2+ in transit, cloud KMS, multi-region encrypted backups.

Access control

SSO + enforced MFA, RBAC with least privilege, JIT elevation, quarterly access reviews.

Application & infrastructure

Secure SDLC, SAST + SCA, periodic pen testing, WAF, network segmentation on GCP.

People & experts

Background checks, mandatory training, NDAs for every Hatch contractor, scoped IP per project.

Incident response

24/7 on-call, IR runbook exercised annually, 72-hour breach notification SLA.

Privacy & global

GDPR Art. 28 ready, CCPA/CPRA compliant, SCCs for international transfers.

Hatch expert controls

Hatch is NobleStark's vetted contractor network. Because expert work product is where customer-confidential signal lives, we treat it with the same controls as production data.

  • • NDA at onboarding before any project access
  • • Per-project scoped NDA and IP terms
  • • Customer data accessed only inside NobleStark-managed environments
  • • Customer model artifacts never used to train internal NobleStark tools
  • • Audit logging on expert access; weekly anomaly review
  • • Customer identity withheld from experts unless authorized

Documents & policies

Reports & artifacts available under NDA

The following are provided to prospective and active customers under a mutual NDA. Email security@noblestark.com and we respond within one business day with an NDA and delivery instructions.

  • • SOC 2 readiness report and current control inventory
  • • Most recent third-party penetration test summary
  • • Security questionnaire (SIG-Lite / CAIQ / custom)
  • • Business continuity / disaster recovery plan overview
  • • Insurance certificates (Cyber Liability and E&O)
  • • Detailed incident response playbook

Get in touch

For security, vulnerability disclosure, customer security reviews, or anything else trust-related, email our security team directly. We respond fast.

security@noblestark.com