TRUST
Security & Compliance
How HouseOfApps protects customer data — encryption, access control, logging, and our compliance roadmap. For questionnaires, DPAs, or pen-test summaries, email hello@houseofapps.ai.
Effective July 13, 2026
Overview
HouseOfApps is built for B2B teams that need CRM, sales, marketing, and AI agents in one workspace without giving up control of their data. Security is designed into the platform: encryption, least privilege, auditability, and customer-controlled LLM keys where BYOK is enabled.
Encryption
- In transit — TLS 1.3 for connections to the marketing site and application.
- At rest — AES-256 encryption for stored customer data in our managed infrastructure.
- Optional BYOK — bring your own keys for LLM providers so model usage stays under your cloud billing and key rotation policies.
Access control
- Role-based access inside customer workspaces
- Internal production access limited to authorized personnel on a need-to-know basis
- Authentication protections for the application, with session controls and credential best practices
Audit & session logs
The platform ships with audit and session logging so teams can review who did what and when. Logs support investigations, compliance reviews, and operational debugging. Retention windows can be discussed for enterprise deployments.
Infrastructure & deployment
HouseOfApps can run on our cloud or, where offered, on your infrastructure. We use reputable cloud providers and industry practices for network isolation, backups, and monitoring.
Availability targets, RPO/RTO, and dedicated deployment options are available on scoping calls for teams with stricter requirements.
Compliance posture
- SOC 2 — formal certification is in progress. Controls are designed toward SOC 2 Trust Services Criteria.
- GDPR-ready — architecture and processes support GDPR obligations; DPAs available on request.
- HIPAA-ready — controls and patterns intended to support HIPAA-aligned deployments where a BAA is executed. Contact us before processing PHI.
“Ready” means the product and operating model are designed to support these frameworks; it does not by itself constitute a completed certification or guarantee of compliance for your use case.
Subprocessors & vendors
We use carefully selected infrastructure, communications, and AI vendors. A current subprocessor list and security questionnaire responses are available for prospects and customers under NDA when required. Email hello@houseofapps.ai.
Incident response
We maintain processes to detect, investigate, contain, and communicate security incidents. Where legally required, we will notify affected customers without undue delay and provide information reasonably needed for your own obligations.
Responsible disclosure
If you believe you have found a vulnerability in HouseOfApps, please email hello@houseofapps.ai with details and steps to reproduce. Do not access data that is not yours or disrupt service while testing. We appreciate good-faith reports and will work with you to validate and remediate.
Security contact
Security & compliance: hello@houseofapps.ai
Related: Privacy Policy · Terms of Service