FAQ
Security and privacy questions
Short answers on where data is hosted, how it is protected, who can see it, and what happens when you leave.
The legal terms are the authority on every point below. This page tells you where to find them and what they say in plain words. If you are filling in a security questionnaire, contact support and you will get answers from the people who built the platform.
Where is our data hosted?
HRS primarily processes customer data in the United States. The core platform (HRS Learn) runs on SiteGround. The simulation engine and HRS Triage run on DigitalOcean, on an isolated platform with its own managed database. Backups and content assets are stored with Amazon Web Services, and Cloudflare provides the edge network in front of the sites.
The current list, with each provider's purpose and location, is the sub-processor register. A provider's location is not a residency guarantee for your tenant. If you need one, ask for it in writing before you sign.
Is our data encrypted?
Yes. Connections use TLS 1.2 or higher, and databases and backups are encrypted at rest. Directory-sync tokens get an extra layer of encryption inside the application. Calls between HRS systems are signed, so one system cannot be impersonated to another.
Is HRS SOC 2 certified?
No. A SOC 2 Type I examination is planned and no completed examination is claimed. Progress is published on the security page rather than implied early. Until then, the controls are described in the Security Addendum and are open to review during an evaluation.
Do you sign a DPA?
The Data Processing Addendum covers GDPR, UK GDPR, the Swiss FADP and CCPA/CPRA. It includes the Standard Contractual Clauses and the UK Addendum for transfers. A PDF copy is linked from that page.
Who at HRS can see our data?
HRS staff have no standing access to a customer organization. Support access is granted per organization, for a limited time, with a reason recorded, and it can be revoked. It is logged on both sides. Administrative access to production systems requires multi-factor authentication.
Who inside our organization can see an individual's results?
Your organization's admins can see each person's training progress, simulation results and personal risk score. If you have imported reporting lines, a manager can be brought in when one of their people repeatedly falls for practice phishing or leaves a policy unacknowledged for a long time. Simulation results record location at country and network level, never city.
People also earn activity points for learning and reporting. Those points, not risk scores, appear on an organization leaderboard of the top 25 people, which anyone signed in to your organization can open. Nothing is visible outside your organization, and MSP clients are isolated from each other. See Roles and what each one can do.
Does HRS store passwords typed into a practice phishing page?
No. Practice sign-in pages discard what is typed into them, and there is no code path that writes a submitted password to storage. The fact that someone submitted is recorded; what they typed is not.
Is our data used to train AI models?
No. HRS does not let its AI providers use customer personal data to train or improve general models, and does not do so itself. See How HRS uses AI.
Can a risk score be used to discipline someone?
HRS doesn't make automated decisions with legal or similarly significant effects on people. The terms say scores must not be the only basis for an employment decision. We'd go further: use the score to decide where to spend training effort, not to judge individuals.
What happens to our data if we leave?
The contract guarantees at least 30 days after it ends to export your data, using the export features or by written request. HRS then deletes it from active systems within 60 days. Aggregated data and routine backups are the exceptions; backups age out on their normal cycle. The exact wording is in section 16 of the Master Services Agreement.
An admin can download a complete export at any time from /account/export in HRS Learn: a ZIP of CSV files covering people, training, simulation results, risk scores, newsletters and the audit log.
Can we delete one person's data?
Yes. Erasing a person anonymizes their record in place, so your reports and audit trail keep their totals without identifying them. The erase screen isn't linked from the people list yet, so contact support and they will take you through it. HRS helps you answer data subject requests and forwards any it receives directly to you, because your organization is the controller of your employees' data.
How do we report a vulnerability?
Email security@humanriskshield.com. The process, scope and response times are in Report a security issue.
Where can I check whether something is down?
The status page runs separately from the platform, so it stays up when the thing it reports on does not.
Related
- How HRS handles your dataWhat each product collects about your people, who controls it, where it is kept, how it is protected and when it is deleted.
- How HRS uses AIWhere AI appears in HumanRisk Shield, which provider it uses, what it can and can't see, and the limits around it.
- Report a security issueHow to report a vulnerability in HumanRisk Shield, what is in scope, and when you will hear back.