TRUST · SECURITY

Designed for easy adoption.

A factual page. Designed to answer your security review’s first ten questions before you ask.

WHO WE ARE

One operating entity.

WORLDWIDE

ImposterHunter AI LTD

Dubai International Financial Centre (DIFC), Dubai, UAE. Registered number 13635, commercial licence CL13635, a private company incorporated under the DIFC Companies Law. Contracting party for all customers worldwide.

RESEARCH & DEVELOPMENT

Bucharest, Romania

Engineering and research operations in the European Union. This is where the detection engine is designed, built, and hardened.

01 · COMPLIANCE ROADMAP

Where we are. Where we're going.

FrameworkStatusTargetAuditor
SOC 2 Type IIIn progressQ4 2026Under selection
ISO 27001Planned2027Pending
HIPAA-ready architectureActivePendingPending
EU AI Act Art. 25 alignmentActivePendingPending
GDPR · CCPAActivePendingPending
02 · SUBPROCESSORS

Who we run on.

VendorPurposeRegion
AWS · BedrockCompute & inferenceUS-East / EU-Central
Google Analytics 4Aggregated traffic measurement (consent-gated, IP anonymized)EU (Google Ireland) → US (SCCs)
DATA RESIDENCY

US or EU. By design.

Region pinning is part of the multi-tenant provisioning model shipping with customer accounts; no cross-region replication without explicit opt-in.

FAIL CLOSED

Errors return errors.

Real signals only. Your application decides how to handle the open case; you stay in control of the policy.

ZERO STATIC KEYS

OIDC-only CI/CD.

Short-lived credentials only, rotated per workflow, scoped to the deploy.

SECURITY CONTACT
security@imposterhunter.com
Coordinated disclosure welcome.

Stop deception before it reaches you.

Book a 30-minute call. We’ll walk through your actual deployment and show you what we’d catch.

Get in touch →
SECURITY REVIEW

Answers your security review asks for.

Which legal entity contracts with my company?

All customers contract with ImposterHunter AI LTD (Dubai International Financial Centre, DIFC, registered number 13635, commercial licence CL13635), a private company incorporated under the DIFC Companies Law.

What is your compliance roadmap?

SOC 2 Type II is in progress with a Q4 2026 target. ISO 27001 is planned for 2027. HIPAA-ready architecture, EU AI Act Article 25 alignment, and GDPR/CCPA controls are active today.

Who are your subprocessors?

AWS Bedrock for compute and inference (US-East and EU-Central). Google Analytics 4 for aggregated, consent-gated, IP-anonymized traffic measurement (EU Google Ireland, with SCCs for US transfer).

Can I pin my data to a specific region?

Yes. Region pinning to US or EU is part of the multi-tenant provisioning model. There is no cross-region replication without explicit opt-in.

How does the API behave on errors?

Fail-closed by design. On any error, the API returns an error, never a false PASS. Real signals only. Your application decides how to handle the open case so you stay in control of the policy.

How are CI/CD credentials managed?

OIDC-only. No static AWS keys exist anywhere in the deploy pipeline. Credentials are short-lived, rotated per workflow, and scoped to the specific deploy.

How do I report a security issue?

Email security@imposterhunter.com. Coordinated disclosure is welcome.