Security, in the open.

How HKR Media SRL protects customer data across HKR.AI — the certifications we hold, the controls we run, and the sub-processors we use.

Compliance

Certified

ISO 27001:2022

Information security management.

Certified

ISO 9001:2015

Quality management.

Compliant

GDPR

EU data protection, EEA-first processing.

In progress

HIPAA

US healthcare data compliance.

Security practices

Endpoint security

  • Company-managed devices with MDM enrollment; BYOD via Zero Trust / VDI or enterprise browser with no local data storage
  • Enterprise browser with encrypted downloads, DLP, and session isolation
  • EDR on all endpoints (Bitdefender GravityZone)
  • Encryption at rest and in transit

Access control

  • Role-based access control (RBAC)
  • Multi-factor authentication enforced
  • Principle of least privilege
  • Regular access reviews

Network & infrastructure

  • 100% cloud-based — no physical servers
  • Hosting on AWS, Microsoft Azure, and Google Cloud, EU regions preferred

Data protection

  • Encryption at rest and in transit
  • EU-based data residency, with Chapter V safeguards for any transfer outside the EEA
  • Data deleted on contract termination or client request
  • No local device storage

People & operations

Personnel security

  • On-demand background checks
  • Confidentiality agreements in every employment and contractor contract
  • Onboarding and offboarding with access revocation

Security awareness

  • Annual mandatory company-wide training
  • Phishing awareness programs
  • Incident reporting procedures

Policies & documentation

  • Information Security Policy
  • Incident Reporting Policy
  • Acceptable Use Policy
  • Access Control Policy
  • Business Continuity Plan

For additional documentation, contact security@hkr.ai.

Sub-processors

The third parties HKR engages to process Customer Personal Data in connection with the Service. This is the list referenced by our Terms of Service and Data Processing Agreement; updates are published here per the notice mechanics in the Terms.

Sub-processorPurposeData location
Amazon Web ServicesCloud infrastructureEU
Microsoft AzureCloud infrastructureEU, Asia
Google CloudCloud infrastructureEU
Google Cloud / Vertex AIAI model processingEU
AnthropicAI model providerUS
VercelWebsite and platform hostingUS, EU
SupabasePlatform databaseEU
Google WorkspaceEmail, documents, collaborationEU
SlackInternal communicationUS
HubSpotCRMEU
NotionDocumentation, project managementUS, EU
HiBobHR managementEU
BitdefenderEndpoint detection & responseEU
Last updated July 8, 2026

Data privacy

  • We are committed to GDPR compliance and do not sell personal information.
  • Personal data submitted as Customer Inputs is processed only on Customers' documented instructions, under our Data Processing Agreement.
  • We do not provide Customer Inputs to third-party AI model providers for training, fine-tuning, or improving their models (ToS §22).
  • AI production runs under human supervision, including curation, review, and final quality control (AUP §9).
  • Standard Contractual Clauses and Transfer Impact Assessments cover any processing outside the EEA.
  • We support data subject access requests under the GDPR and assist with CCPA/CPRA obligations.

Security questions: security@hkr.ai. Privacy requests: privacy@hkr.ai.