Trust
Security
What we do to protect your data, stated plainly — including the parts of the programme that are still ahead of us.
An honest starting point. ExactHue is a pre-seed company founded in 2025. We would rather tell you exactly which controls are operating today and which are on the roadmap than display a wall of badges we have not earned. Everything on this page is either in place now or explicitly marked as planned.
Data protection in the product
- Captures are not retained. An image submitted to ExactHue Core is processed to produce the match result and then deleted. Retention for model improvement happens only where a customer has explicitly opted in under a separate written agreement.
- No biometric identification. The engine does not perform facial recognition or verification and does not generate a face template. It measures colour from skin regions.
- Region pinning. Enterprise customers can pin processing to EU, UK, US or APAC regions so capture data does not leave the chosen region during processing.
- Derived data minimisation. Match results are aggregated and de-identified within 30 days; what remains cannot reasonably be linked back to an individual.
- Catalogue portability. Your measured catalogue is exportable in an open format at any time and on termination.
Infrastructure and encryption
- TLS 1.2 or above for all data in transit, with HSTS enabled on exacthue.com.
- AES-256 encryption at rest for stored data and backups.
- Managed cloud infrastructure in ISO 27001-certified facilities, with per-environment network isolation.
- Secrets held in a managed secret store, never in source control or environment files committed to a repository.
- Automated encrypted backups with periodic restore testing.
Access control
- Least-privilege access, granted by role and reviewed quarterly.
- Multi-factor authentication mandatory for all staff accounts and all administrative access.
- API credentials scoped per environment, so a sandbox key cannot reach production data.
- Production access is logged; access to customer data requires a documented reason.
- Offboarding revokes all access on the final working day.
- Single sign-on (SAML 2.0 / OIDC) and customer-visible audit logging available on Enterprise plans.
Development practices
- Every change to production code is reviewed by a second engineer before it ships.
- Dependency and vulnerability scanning runs automatically, with a remediation window set by severity.
- Secret scanning runs before code reaches a shared branch, so credentials do not end up in history.
- Development, sandbox and production are separate environments and share no credentials.
- Infrastructure is defined as code, which is what makes a change reviewable and a mistake reversible.
Incident response
We maintain a documented incident response process with defined severity levels, an on-call rotation and a named incident lead. If a security incident affects your data:
- we will contain first and investigate immediately;
- we will notify affected customers without undue delay, and in any event within 72 hours of becoming aware where a notification obligation applies;
- we will provide what we know, what we do not yet know, and what we are doing — and update as that changes;
- we will publish a post-incident review to affected customers, including root cause and corrective actions.
Sub-processors
We use a small number of service providers to run the service — cloud hosting, email delivery, payment processing, and error monitoring. Each operates under a written contract restricting them to our instructions.
A current sub-processor list is available to customers on request. Enterprise agreements include a contractual obligation to notify you before a new sub-processor takes effect, with a right to object.
What is not in place yet
Stating this openly is more useful to your security review than omitting it.
| Control | Status |
|---|---|
| SOC 2 Type II attestation | Planned. Not yet commenced; we will not claim it before an auditor signs it. |
| ISO 27001 certification | Planned. Our infrastructure providers are certified; ExactHue as an organisation is not yet. |
| Independent penetration test | Planned before first production Enterprise deployment. |
| Public bug bounty programme | Not yet. Responsible disclosure below is the current route. |
| Customer-facing status page | In progress. |
| A dedicated security hire | Not yet. Security is owned by the engineering team, and the founder is accountable for it. |
Responsible disclosure
If you believe you have found a vulnerability, we want to hear from you and we will not pursue legal action against good-faith research that follows this policy.
Please do
- Email security@exacthue.com with enough detail to reproduce the issue.
- Give us reasonable time to remediate before any public disclosure — 90 days is our default request.
- Test only against your own account or our sandbox environment.
Please do not
- Access, modify or delete data belonging to anyone else.
- Run denial-of-service, volumetric or automated brute-force testing against production.
- Use social engineering, phishing or physical intrusion against our staff or premises.
- Publish details before we have had a chance to fix the issue.
We acknowledge reports within two business days, keep you updated on remediation, and will credit you publicly if you would like that.
Security review questions
If your organisation runs a vendor security assessment, write to security@exacthue.com. We will complete your questionnaire, provide our data-processing agreement, and answer follow-ups directly rather than pointing you at a portal.
ExactHue Pte. Ltd. · 352 Yishun Ring Road, Singapore 760352