Encryption in transit
TLS 1.2+ on all API, widget, and dashboard traffic.
Agents that remember people should be clear about data. Here is what Humaner processes, what we save, and what we never touch.
Managed infrastructure with encryption, isolation, and least-privilege access at every layer.
TLS 1.2+ on all API, widget, and dashboard traffic.
Postgres and Redis encrypt data at rest on managed infrastructure.
OAuth and email auth with secure, httpOnly session cookies.
API keys and provider credentials live in environment variables.
Default 90-day visitor message retention with scheduled deletion.
Humaner links each control directly into your agents — enforced before a single token is generated.
Humaner
No knowledge match, no guess — the agent asks or declines.
Forbidden topics enforced in every system prompt.
Widgets only load on origins you explicitly approve.
Per-IP, per-session, and per-agent throttling before LLM calls.
Knowledge, chats, and embeddings never cross tenant boundaries.
Processed to run your workspace and deliver support — never sold, and never used to train third-party foundation models.
Visitor chat messages
Messages, timestamps, and session metadata for support delivery.
Cross-session memory
Context your agent keeps when memory is enabled for a visitor.
Workspace & account data
Email, organization profile, team members, and agent settings.
Knowledge you upload
Docs, URLs, PDFs, and embeddings that ground your agents.
Desk & analytics signals
Escalations, resolutions, and usage metrics inside your workspace.
Credit card numbers
Billing runs through Polar — Humaner does not store card data.
Personal health information
Blocked by industry guardrails; agents decline medical advice.
Selling conversation data
We do not sell or license your customers' messages.
Third-party model training
Your content is not used to train shared foundation models.
We are happy to walk through architecture, data flows, and controls. For privacy-specific requests, see our Privacy Policy, DPA, and Terms of Service.