Trust & security

Built to trust.
Honest by design.

The questions a technical evaluator asks before they convert — answered with what's actually true today. No fake badges.

no cross-tenant leaks · audited1.7KB sandboxed · CORS-gated

Shared setup

Security is a shared setup. You stay in control.

You decide what it can do and see. We keep the platform locked down underneath.

We ensure

Per-site isolation

Row-level security — no cross-tenant reads.

Sandboxed embed

~1.7KB in a shadow root — can't touch your DOM or styles.

Encrypted

TLS in transit; encrypted at rest (Postgres).

Grounded answers

Never invents — unsure → it hands off.

Access fails closed

Least-privilege, deny by default.

You control

What it says

Your Conversion Strategy is the playbook.

Where it loads

A CORS allow-list of your domains.

What it captures

Per-site — toggle capture off anytime.

Pause or delete

Stop the widget or purge the whole site.

Your data

Export or delete it whenever you want.

The model

Your data never leaves its own lane.

One tiny sandboxed script talks only to your site's own, row-locked data. Nothing bleeds across tenants — by construction, not by policy.

Visitor

Asks on your page

Sandboxed widget

~1.7KB · shadow root · CORS

Your site

DOM & styles untouched

Your data

Per-site · row-locked

In place today

Real controls, not fake badges.

What's actually running now — grouped the way an evaluator reviews it.

Isolation

  • Row-level security, scoped per site
  • CORS-gated origins you control

Encryption

  • TLS 1.2+ in transit
  • Encrypted at rest — Supabase Postgres

Access

  • Least-privilege roles, deny by default
  • Magic-link + Google / GitHub sign-in

Data

  • Export & delete anytime, per site
  • Never sold; never trains shared models

Answers

  • Grounded in your own content
  • Honest hand-off — no fabrication

On the roadmap

Not yet in place — and we'll say so.

We won't claim certifications we don't have. Here's what we're working toward — ask us where any of it stands.

SOC 2 Type II

Formal audit of our controls.

Planned

GDPR DPA + regional controls

Standard DPA + data-processing tooling.

Planned

SSO / SAML for the cabinet

Enterprise sign-in for teams.

Planned

Independent penetration test

Third-party pen test + published report.

Planned

Formal SLA

A published uptime commitment we can stand behind.

Planned

Our promise

It never bluffs about your product.

When Hintli isn't sure, it says so and hands the visitor to you — it will not invent an answer about your business. That's the guarantee that matters most while everything else is still on the way.

FAQ

Straight answers, no asterisks.

What compliance certifications do you have?

None yet — we're pilot-stage and won't fake a badge. SOC 2, a GDPR DPA and an external pen test are on the roadmap. Underneath, today, we run per-site row-level isolation, TLS, encryption at rest, and least-privilege access.

How do you prevent hallucinations or unsafe answers?

Answers are grounded in your own content. When Hintli isn't sure, it hedges and hands the visitor off — it won't invent facts about your product.

Do you use my data to train shared AI models?

No. Your data is isolated per site and is never used to train models shared across customers. We don't sell it either.

Where is my data stored, and is it encrypted?

Managed Postgres (Supabase), encrypted at rest and served over TLS, isolated per site with row-level security.

Can I export or delete my data?

Yes — anytime, per site. You can also pause the widget or fully delete a site (30-day purge).

What's your uptime / SLA?

We run on managed infrastructure (Vercel + Supabase) with no single point of failure, but we don't publish a formal SLA yet — we won't promise a number we can't stand behind at pilot stage.

A security question, or found something?

Talk to us — we answer security and data questions from real evaluators directly, before any call.