Your data never trains a model
Vendor submissions and RFP content are used only to score your evaluations, never to train or fine-tune any AI model.
HillStar keeps sensitive RFPs and vendor responses secure through encryption and isolated workspaces. We will never train on your data.
All sub-processors are SOC 2 certified, with our own certification expected Q3 2026.
Data is encrypted in transit (TLS 1.3) and at rest (AES-256), hosted entirely in the United States.
Role-based permissions and workspace isolation, with every action logged and timestamped for review.
Every evaluation links back to its source evidence and the reasoning that produced it.
Security is built into every layer of HillStar, from infrastructure and workspace isolation to model usage, access controls, and independent testing.
Vendor submissions and RFP content are used only to score your evaluations, never to train or fine-tune any AI model.
Your data never leaves the United States. Document processing, storage, and AI inference are pinned to US-region infrastructure — enforced in code, not just policy, and verified on every deploy. Other regions may be supported with an enterprise agreement.
Every project, file, and score is scoped to your workspace. Access is verified on each request against workspace membership and role — no shared links, no cross-tenant leakage, all access logged.
HillStar undergoes semi-annual third-party penetration tests covering the full platform, backed by continuous SAST scanning and image-level vulnerability monitoring across our entire registry.
HillStar runs on Google Cloud and uses its managed infrastructure and encryption controls.
These same answers, plus how evaluations and scoring work, are on the frequently asked questions page.
| Question | Answer |
|---|---|
| Can other customers see my data? | No. Strict workspace isolation at the database and API layers. |
| Can HillStar employees see my data? | No. Access requires explicit customer permission for support. |
| Where is my data stored? | Google Cloud Platform, US region. |
| Is my data encrypted? | Yes. At rest (AES-256) and in transit (TLS 1.3). |
| Does AI training use my data? | No. HillStar will never train on your data. Our AI partners do not use commercial prompts or outputs for model training by default. |
| Do you have SOC 2? | SOC 2 is in progress, with completion targeted for Q3 2026. HillStar Trust Center |
Review our security, privacy, compliance, and data-handling practices in one place.