Trust & security
The questions a technical evaluator asks before they convert — answered with what's actually true today. No fake badges.
Shared setup
You decide what it can do and see. We keep the platform locked down underneath.
We ensure
Per-site isolation
Row-level security — no cross-tenant reads.
Sandboxed embed
~1.7KB in a shadow root — can't touch your DOM or styles.
Encrypted
TLS in transit; encrypted at rest (Postgres).
Grounded answers
Never invents — unsure → it hands off.
Access fails closed
Least-privilege, deny by default.
You control
What it says
Your Conversion Strategy is the playbook.
Where it loads
A CORS allow-list of your domains.
What it captures
Per-site — toggle capture off anytime.
Pause or delete
Stop the widget or purge the whole site.
Your data
Export or delete it whenever you want.
The model
One tiny sandboxed script talks only to your site's own, row-locked data. Nothing bleeds across tenants — by construction, not by policy.
Visitor
Asks on your page
Sandboxed widget
~1.7KB · shadow root · CORS
Your site
DOM & styles untouched
Your data
Per-site · row-locked
In place today
What's actually running now — grouped the way an evaluator reviews it.
Isolation
Encryption
Access
Data
Answers
On the roadmap
We won't claim certifications we don't have. Here's what we're working toward — ask us where any of it stands.
SOC 2 Type II
Formal audit of our controls.
GDPR DPA + regional controls
Standard DPA + data-processing tooling.
SSO / SAML for the cabinet
Enterprise sign-in for teams.
Independent penetration test
Third-party pen test + published report.
Formal SLA
A published uptime commitment we can stand behind.
Our promise
When Hintli isn't sure, it says so and hands the visitor to you — it will not invent an answer about your business. That's the guarantee that matters most while everything else is still on the way.
FAQ
None yet — we're pilot-stage and won't fake a badge. SOC 2, a GDPR DPA and an external pen test are on the roadmap. Underneath, today, we run per-site row-level isolation, TLS, encryption at rest, and least-privilege access.
Answers are grounded in your own content. When Hintli isn't sure, it hedges and hands the visitor off — it won't invent facts about your product.
No. Your data is isolated per site and is never used to train models shared across customers. We don't sell it either.
Managed Postgres (Supabase), encrypted at rest and served over TLS, isolated per site with row-level security.
Yes — anytime, per site. You can also pause the widget or fully delete a site (30-day purge).
We run on managed infrastructure (Vercel + Supabase) with no single point of failure, but we don't publish a formal SLA yet — we won't promise a number we can't stand behind at pilot stage.
Talk to us — we answer security and data questions from real evaluators directly, before any call.