Skip to main content
Book a Demo
Trust & Security

Security is not a feature. It's the architecture.

Dehurdle was designed from day one to pass enterprise security reviews. Zero-payload privacy means no employee private data ever reaches an LLM provider.

Compliance

Frameworks & Standards

SOC 2 Type II

Aligned

Architecture designed to Trust Services Criteria across security, availability, processing integrity, confidentiality, and privacy.

ISO 27001

Aligned

Information security management practices aligned with international standards for systematic risk management.

GDPR

Aligned

Platform designed to EU General Data Protection Regulation standards, including data minimization, right to erasure, and DPO appointment.

India DPDP Act

Aligned

Architecture aligned with India's Digital Personal Data Protection Act 2023, including consent management and cross-border transfer controls.

EU AI Act

Aligned

AI subsystems classified by risk tier. High-risk components include human-in-the-loop escalation protocols.

Zero-Payload Architecture

What Data Goes Where

The coaching engine operates on its own conversational context. It never accesses employee emails, internal chats, or private work data.

Employee

Sends coaching message

Dehurdle API

Sanitizes input, prepares coaching context

LLM Provider

Receives coaching context only — no emails, chats, or work data

Dehurdle API

Stores behavioral signals, returns coaching response

What We Never Access

  • Employee emails or inbox content
  • Internal Slack/Teams messages or channels
  • Documents, files, or shared drives
  • Calendar event content or attendee details
  • Browsing history or app usage data
  • Biometric data of any kind

What We Do Process

  • Coaching conversations (within Dehurdle only)
  • Behavioral signals from coaching interactions
  • Goal and activity progress data
  • Aggregated competency scores
  • Consent-gated organizational insights
  • Calendar metadata (time slots only — no content)

Infrastructure

Enterprise-Grade Foundation

Cloud Infrastructure

  • Google Cloud Platform & AWS
  • Data residency: user data stays in the user's region
  • Regional hosting available per compliance requirements
  • Automatic scaling and redundancy
  • 99.9% uptime SLA

Encryption

  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • Per-organization encryption keys
  • Integration tokens encrypted via AES-256-GCM

Audit & Governance

  • Complete audit trail for all admin actions
  • Immutable log storage
  • Role-based access control (RBAC)
  • Data export and deletion APIs

EU AI Act

AI Risk Classification

Every AI subsystem in Dehurdle is classified under the EU AI Act risk framework with appropriate safeguards.

SubsystemRisk TierRationaleSafeguard
Pattern ClassificationLowRule-based processing. No personal data processed.Fully auditable decision logic.
Coaching ConversationsLimitedDirect user interaction with transparent AI identity.Users informed they are interacting with AI.
Safety MonitoringHighSafety-critical. Affects user wellbeing.Mandatory human-in-the-loop escalation.
Development AnalyticsHighPotential employment impact.Consent-gated. Opt-in only. Aggregated when not consented.

Security Review

Pass your security review.

Book a technical walkthrough with our team. We'll walk your CISO through the architecture in 30 minutes.

Book a Security Review

We use cookies

We use cookies to enhance your experience and analyze our traffic. You can accept, reject, or customize your preferences.