Trust centre

What we do with your data.

Plain language, no jargon: what is true today, what is on the roadmap, and what we do not have. Every claim on this page is one we will stand behind in a procurement review.

Posture at a glance
Certifications
None held today
Data residency
Singapore only
Bug bounty
Not yet — disclosure inbox only
Incidents to date
None reported

Certification status is stated first on purpose — see the note below.

Current protections

  • Encryption in transit (TLS 1.2+ with HSTS) and at rest.
  • Access controls restricting personal data to authorized personnel who need it.
  • Data residency in Singapore, with backups held in-region.
  • No training of AI models on user data, and no sale of user data.
  • Daily encrypted backups with point-in-time recovery.

What we do not have yet

HokAI is not SOC 2 Type II certified, not ISO 27001 certified, and does not offer a HIPAA BAA. We will never claim a certification we do not hold — if your procurement requires one, email Hokai@aioasia.com and we will tell you exactly where we are on each.

Reporting a vulnerability

See our security.txt for the authorized vulnerability disclosure path, or email Hokai@aioasia.com.