Security first.

Agents that remember people should be clear about data. Here is what Humaner processes, what we save, and what we never touch.

Encryption & infrastructure

Managed infrastructure with encryption, isolation, and least-privilege access at every layer.

Encryption in transit

TLS 1.2+ on all API, widget, and dashboard traffic.

Encryption at rest

Postgres and Redis encrypt data at rest on managed infrastructure.

Authentication

OAuth and email auth with secure, httpOnly session cookies.

Secrets management

API keys and provider credentials live in environment variables.

Retention & purge

Default 90-day visitor message retention with scheduled deletion.

Built into every agent

Humaner links each control directly into your agents — enforced before a single token is generated.

Humaner

  • Strict grounding gate

    No knowledge match, no guess — the agent asks or declines.

  • Industry guardrails

    Forbidden topics enforced in every system prompt.

  • Domain allowlist

    Widgets only load on origins you explicitly approve.

  • Rate limits

    Per-IP, per-session, and per-agent throttling before LLM calls.

  • Workspace isolation

    Knowledge, chats, and embeddings never cross tenant boundaries.

Data scope

Processed to run your workspace and deliver support — never sold, and never used to train third-party foundation models.

Visitor chat messages

Messages, timestamps, and session metadata for support delivery.

Cross-session memory

Context your agent keeps when memory is enabled for a visitor.

Workspace & account data

Email, organization profile, team members, and agent settings.

Knowledge you upload

Docs, URLs, PDFs, and embeddings that ground your agents.

Desk & analytics signals

Escalations, resolutions, and usage metrics inside your workspace.

Credit card numbers

Billing runs through Polar — Humaner does not store card data.

Personal health information

Blocked by industry guardrails; agents decline medical advice.

Selling conversation data

We do not sell or license your customers' messages.

Third-party model training

Your content is not used to train shared foundation models.

Questions about security?

We are happy to walk through architecture, data flows, and controls. For privacy-specific requests, see our Privacy Policy, DPA, and Terms of Service.