Trust Center
Security, in the open.
How HKR Media SRL protects customer data across HKR.AI — the certifications we hold, the controls we run, and the sub-processors we use.
Compliance
Certified
ISO 27001:2022
Information security management.
Certified
ISO 9001:2015
Quality management.
Compliant
GDPR
EU data protection, EEA-first processing.
In progress
HIPAA
US healthcare data compliance.
Security practices
Endpoint security
- Company-managed devices with MDM enrollment; BYOD via Zero Trust / VDI or enterprise browser with no local data storage
- Enterprise browser with encrypted downloads, DLP, and session isolation
- EDR on all endpoints (Bitdefender GravityZone)
- Encryption at rest and in transit
Access control
- Role-based access control (RBAC)
- Multi-factor authentication enforced
- Principle of least privilege
- Regular access reviews
Network & infrastructure
- 100% cloud-based — no physical servers
- Hosting on AWS, Microsoft Azure, and Google Cloud, EU regions preferred
Data protection
- Encryption at rest and in transit
- EU-based data residency, with Chapter V safeguards for any transfer outside the EEA
- Data deleted on contract termination or client request
- No local device storage
People & operations
Personnel security
- On-demand background checks
- Confidentiality agreements in every employment and contractor contract
- Onboarding and offboarding with access revocation
Security awareness
- Annual mandatory company-wide training
- Phishing awareness programs
- Incident reporting procedures
Policies & documentation
- Information Security Policy
- Incident Reporting Policy
- Acceptable Use Policy
- Access Control Policy
- Business Continuity Plan
For additional documentation, contact security@hkr.ai.
Sub-processors
The third parties HKR engages to process Customer Personal Data in connection with the Service. This is the list referenced by our Terms of Service and Data Processing Agreement; updates are published here per the notice mechanics in the Terms.
| Sub-processor | Purpose | Data location |
|---|---|---|
| Amazon Web Services | Cloud infrastructure | EU |
| Microsoft Azure | Cloud infrastructure | EU, Asia |
| Google Cloud | Cloud infrastructure | EU |
| Google Cloud / Vertex AI | AI model processing | EU |
| Anthropic | AI model provider | US |
| Vercel | Website and platform hosting | US, EU |
| Supabase | Platform database | EU |
| Google Workspace | Email, documents, collaboration | EU |
| Slack | Internal communication | US |
| HubSpot | CRM | EU |
| Notion | Documentation, project management | US, EU |
| HiBob | HR management | EU |
| Bitdefender | Endpoint detection & response | EU |
Last updated July 8, 2026
Data privacy
- We are committed to GDPR compliance and do not sell personal information.
- Personal data submitted as Customer Inputs is processed only on Customers' documented instructions, under our Data Processing Agreement.
- We do not provide Customer Inputs to third-party AI model providers for training, fine-tuning, or improving their models (ToS §22).
- AI production runs under human supervision, including curation, review, and final quality control (AUP §9).
- Standard Contractual Clauses and Transfer Impact Assessments cover any processing outside the EEA.
- We support data subject access requests under the GDPR and assist with CCPA/CPRA obligations.
Security questions: security@hkr.ai. Privacy requests: privacy@hkr.ai.