Skip to main content
Security is foundational to Hercules. You trust us with your apps, your data, and your users’ data, and we treat protecting them as a core part of the product. This page describes the security practices behind the Hercules platform. For how personal data is collected and used, see the Privacy Policy. For enterprise controls such as SSO, SCIM, and audit logs, see Enterprise. To report a vulnerability, email security@hercules.app.

How is customer data protected?

  • Encryption in transit. All traffic to Hercules and to apps published on Hercules uses TLS. Apps can enforce HTTPS with security headers such as HSTS.
  • Encryption at rest. Databases, file storage, and backups are encrypted at rest. Secrets, API keys, and OAuth tokens are encrypted with separate keys and are never shown again after they are saved.
  • Tenant isolation. Each organization’s apps, data, and dev machines are logically isolated. Apps cannot read another app’s data.
  • Data residency. Apps can be hosted in the United States or Europe. See Enterprise for details.
  • Backups. Platform data is backed up automatically. App databases can run scheduled backups with managed retention.
  • Deletion. When you delete an app or organization, the data is removed from our production systems and ages out of backups on a fixed schedule.

Where is Hercules hosted?

Hercules runs on leading cloud providers, including Amazon Web Services and Cloudflare, in facilities that hold their own independent security certifications. We use their managed services for compute, storage, networking, and key management.
  • Production infrastructure is defined as code and deployed through reviewed, automated pipelines.
  • Production networks are segmented. Databases and internal services are not reachable from the public internet.
  • Published apps run on globally distributed, serverless infrastructure that scales automatically and absorbs traffic spikes and denial-of-service attempts.

Who can access customer data?

  • Least privilege. Employees get the access needed for their role, and production access is limited to the engineers who need it.
  • Authentication. Internal systems are behind single sign-on, and multi-factor authentication is required for accounts with production access.
  • Access logging. Access to production systems is logged, and access is removed when someone changes roles or leaves the company.
  • Support access. Hercules staff access customer apps and data to resolve a support request or a security issue, and limit that access to what the issue requires.

How do you secure the product itself?

  • Secure development. Automated tests, static analysis, and dependency scanning run on every change, and changes ship through automated pipelines.
  • Dependency and supply chain. Third-party packages are continuously scanned for known vulnerabilities and license risk, and pinned so builds are reproducible.
  • Secrets management. Credentials are stored in managed secret stores, never in source code, and are rotated on a schedule and whenever exposure is suspected.
  • Sandboxed execution. Code generated and run by the Hercules Agent runs in isolated dev machines with no access to other customers’ environments.

How do you monitor for and respond to incidents?

  • Monitoring. Production systems are monitored around the clock for availability, errors, and anomalous behavior. Security-relevant events are centrally logged and alerted on.
  • Incident response. We maintain a documented incident response process with defined severity levels, on-call engineers, and escalation paths. Every incident gets a post-incident review.
  • Customer notification. If an incident affects your data, we notify affected customers without undue delay and share what happened, what was affected, and what we changed.
  • Business continuity. Backups are tested, infrastructure is redundant across availability zones, and we maintain recovery plans for our critical systems.

How do you manage vendors?

Every vendor that stores or processes customer data is reviewed before onboarding and reassessed periodically. We look at their certifications, data handling practices, and contractual commitments, and we limit the data each vendor receives to what it needs.

What compliance standards do you follow?

Enterprise customers can request our latest audit reports and security questionnaire responses by contacting sales@hercules.app.

How do I report a vulnerability?

We welcome reports from security researchers and customers. Email security@hercules.app with steps to reproduce the issue. We acknowledge reports quickly, keep you updated while we investigate, and credit researchers who report in good faith. Please do not access data that is not yours, disrupt the service, or publicly disclose an issue before we have fixed it.

Additional FAQ

Yes, under NDA once the audit is complete. Until then we can share our current controls and answers to standard questionnaires. Contact sales@hercules.app.
All data is stored securely by Hercules. For full details on how personal data (including for minors) is handled, see the Privacy Policy. If you have specific compliance requirements (COPPA, FERPA, and similar), contact sales@hercules.app.
Hercules does not currently support HIPAA, HITECH, or FERPA compliance. HIPAA support is on the roadmap for early 2027. No timeline has been announced for FERPA or HITECH. For regulated data use cases (healthcare, education), contact sales@hercules.app to discuss what is possible today.
Read our Terms and Privacy Policy.