How is customer data protected?
- Encryption in transit. All traffic to Hercules and to apps published on Hercules uses TLS. Apps can enforce HTTPS with security headers such as HSTS.
- Encryption at rest. Databases, file storage, and backups are encrypted at rest. Secrets, API keys, and OAuth tokens are encrypted with separate keys and are never shown again after they are saved.
- Tenant isolation. Each organization’s apps, data, and dev machines are logically isolated. Apps cannot read another app’s data.
- Data residency. Apps can be hosted in the United States or Europe. See Enterprise for details.
- Backups. Platform data is backed up automatically. App databases can run scheduled backups with managed retention.
- Deletion. When you delete an app or organization, the data is removed from our production systems and ages out of backups on a fixed schedule.
Where is Hercules hosted?
Hercules runs on leading cloud providers, including Amazon Web Services and Cloudflare, in facilities that hold their own independent security certifications. We use their managed services for compute, storage, networking, and key management.- Production infrastructure is defined as code and deployed through reviewed, automated pipelines.
- Production networks are segmented. Databases and internal services are not reachable from the public internet.
- Published apps run on globally distributed, serverless infrastructure that scales automatically and absorbs traffic spikes and denial-of-service attempts.
Who can access customer data?
- Least privilege. Employees get the access needed for their role, and production access is limited to the engineers who need it.
- Authentication. Internal systems are behind single sign-on, and multi-factor authentication is required for accounts with production access.
- Access logging. Access to production systems is logged, and access is removed when someone changes roles or leaves the company.
- Support access. Hercules staff access customer apps and data to resolve a support request or a security issue, and limit that access to what the issue requires.
How do you secure the product itself?
- Secure development. Automated tests, static analysis, and dependency scanning run on every change, and changes ship through automated pipelines.
- Dependency and supply chain. Third-party packages are continuously scanned for known vulnerabilities and license risk, and pinned so builds are reproducible.
- Secrets management. Credentials are stored in managed secret stores, never in source code, and are rotated on a schedule and whenever exposure is suspected.
- Sandboxed execution. Code generated and run by the Hercules Agent runs in isolated dev machines with no access to other customers’ environments.
How do you monitor for and respond to incidents?
- Monitoring. Production systems are monitored around the clock for availability, errors, and anomalous behavior. Security-relevant events are centrally logged and alerted on.
- Incident response. We maintain a documented incident response process with defined severity levels, on-call engineers, and escalation paths. Every incident gets a post-incident review.
- Customer notification. If an incident affects your data, we notify affected customers without undue delay and share what happened, what was affected, and what we changed.
- Business continuity. Backups are tested, infrastructure is redundant across availability zones, and we maintain recovery plans for our critical systems.
How do you manage vendors?
Every vendor that stores or processes customer data is reviewed before onboarding and reassessed periodically. We look at their certifications, data handling practices, and contractual commitments, and we limit the data each vendor receives to what it needs.What compliance standards do you follow?
Enterprise customers can request our latest audit reports and security questionnaire responses by contacting sales@hercules.app.
How do I report a vulnerability?
We welcome reports from security researchers and customers. Email security@hercules.app with steps to reproduce the issue. We acknowledge reports quickly, keep you updated while we investigate, and credit researchers who report in good faith. Please do not access data that is not yours, disrupt the service, or publicly disclose an issue before we have fixed it.Additional FAQ
Can I get a copy of your SOC 2 report or fill out a security questionnaire?
Can I get a copy of your SOC 2 report or fill out a security questionnaire?
Yes, under NDA once the audit is complete. Until then we can share our current controls and
answers to standard questionnaires. Contact sales@hercules.app.
Does Hercules comply with children's data privacy regulations (COPPA)?
Does Hercules comply with children's data privacy regulations (COPPA)?
All data is stored securely by Hercules. For full details on how personal data (including for
minors) is handled, see the Privacy Policy. If you have
specific compliance requirements (COPPA, FERPA, and similar), contact
sales@hercules.app.
Is Hercules FERPA or HITECH compliant?
Is Hercules FERPA or HITECH compliant?
Hercules does not currently support HIPAA, HITECH, or FERPA compliance. HIPAA support is on the
roadmap for early 2027. No timeline has been announced for FERPA or HITECH. For regulated data use
cases (healthcare, education), contact sales@hercules.app to discuss
what is possible today.
Where can I find your terms and privacy policy?
Where can I find your terms and privacy policy?
Read our Terms and
Privacy Policy.