Trust Center

Everything an assessor — or a buyer’s security team — asks for, in one place.

We are deliberate about the difference between what HoundShield is built for and what it is formally certified against. Below is the honest version: framework alignment, our SOC 2 roadmap, who processes data on our behalf, and how to reach our security team.

Framework alignment

  • CMMC Level 2 / NIST 800-171 Rev 2

    Built for

    All 110 controls mapped for SPRS scoring; the product is engineered as a control for SC.3.177, AU.2.041, AC.L2-3.1.x.

  • HIPAA

    Built for

    Local PHI detection + audit trail. A BAA applies only to self-hosted (Mode B) deployments; the hosted trial is for non-PHI evaluation.

  • DFARS 252.204-7012

    Built for

    Local-only scanning keeps CUI inside the boundary — the asymmetric advantage over cloud DLP.

  • SOC 2 Type I

    In progress

    Audit planned via Vanta/Drata. We do NOT claim a SOC 2 report today — this page will link the attestation the moment it exists.

  • ISO 27001

    Planned

    Control mapping maintained; formal certification is a later-stage roadmap item.

“Built for” means engineered to satisfy the controls; it is not a third-party attestation. We will never publish a certification we do not hold.

Where your data lives

For regulated workloads, run Mode B — the proxy in your own infrastructure, where prompt content never crosses your boundary. The hosted trial is for non-CUI/non-PHI evaluation only.

Handling CUI? Run Mode B.

HoundShield scans prompts locally in under 10ms. That CUI-safe property holds only when the scanner runs inside your own boundary. Pick the deployment mode that matches your data:

A · Hosted trial

On Vercel — not FedRAMP-authorized. Demo and non-CUI evaluation only.

B · Self-hosted Docker

Your own infrastructure. CUI-safe — prompt content never leaves your boundary. Right for CUI-handling contractors.

C · Air-gapped

Isolated network. CUI-safe. For enterprise / IL-5+ environments.

Subprocessors

These vendors process control-plane data (account, billing, metadata) on our behalf. They never receive your prompt content, which is scanned locally in Mode B. Full terms are in the DPA.

  • SupabaseAuthentication & metadata database (US region)
  • VercelMarketing/dashboard hosting & edge network
  • StripePayment processing
  • ResendTransactional email

Security questions or a vendor review?

Email security@houndshield.com for our security questionnaire responses, or legal@houndshield.com for a countersigned DPA. Want to see the evidence the product produces? Download a sample report (PDF).