Security & Compliance

Security is built into everything we do

hunterAI is committed to protecting the healthcare procurement and financial data of every organization we serve. Our security program is independently certified and continuously monitored — not just documented once a year.

How we protect your data

01

Cloud infrastructure

Hosted on AWS within a secured Virtual Private Cloud (VPC), with role-based access and monitored administrative access via Bastion Host.

02

Encryption

Data encrypted at rest and in transit.

03

Access control

Role-based access, multi-factor authentication, and least-privilege principles across all systems.

04

Monitoring

Continuous monitoring via AWS CloudTrail, GuardDuty, and Security Hub, with defined incident response procedures.

05

People & process

Background-verified hires, mandatory security training, and documented policies covering every stage of our data lifecycle — from access provisioning to secure disposal.

Subprocessors & infrastructure

hunterAI relies on the following subservice organizations to support our platform:

Amazon Web Services (AWS)Cloud infrastructure, compute, storage, monitoring
Microsoft AzureSupporting business and operational processes
ZohoBusiness operations and ticketing

Why hunterAI invested in ISO 27001 and SOC 2

Want the deeper story behind these certifications — why we pursued them, what changed internally, and what it means for how we handle your data? Read our companion blog post, “Why hunterAI Invested in ISO 27001 and SOC 2 — A Note from Our CTO,” by Dr. Vegi, CTO & Co-Founder.

Read CTO note

Frequently asked questions

What's the difference between SOC 2 Type I and Type II?

Type I is a snapshot — it confirms our controls were properly designed on a specific date. Type II goes further, confirming those controls operated effectively over a period of months. hunterAI holds both.

Who audits hunterAI?

Our ISO 27001 certification was issued by InterCert (Texas, USA). Our SOC 2 examination was conducted by ShieldByte Infosec Pvt. Ltd. (India) with independent attestation by House of CPA Firm (New York, USA).

Can I get a copy of the full audit report?

Yes — SOC 2 reports and supporting documentation are available under NDA. Talk to the hunterAI team to request access.

How often are these certifications renewed?

ISO 27001 requires annual surveillance audits with full recertification every 3 years. SOC 2 Type II is re-audited annually to maintain continuous coverage.