Built to be trusted with your customers.

Hobson reads and answers your customers’ messages, so it is built to handle that data carefully and to keep the AI on a short leash.

Data and hosting

  • Where data lives

    Email and files are stored with Amazon Web Services in Ireland (eu-west-1). The API runs on Hetzner in the EU, the database on Neon and the web app on Vercel.

  • AI providers

    Drafting uses Anthropic and search uses Voyage AI, both in the United States under standard contractual clauses. Documents are read by Reducto’s EU service.

  • Encryption

    Traffic is encrypted in transit. OAuth tokens and API keys are encrypted at rest with AES-256-GCM, each with its own key, wrapped by a master key held outside the database.

  • Workspace isolation

    Every query is scoped to your workspace in one place in our code, and each new table gets an isolation test.

Keeping the AI in check

  • Messages are data, not instructions

    Every inbound message is checked for attempts to manipulate the AI, including hidden text. Flagged conversations get no tools or order actions and go to a person.

  • Knowledge is checked too

    Documents and web pages you add are checked the same way. A suspicious source is held back until an owner or admin allows it.

  • Approval before action

    Order changes and custom actions only run when a person approves the reply. Agents have money limits.

  • Checks before sending

    Drafts are checked for unbacked claims, policy sentences and personal data. Auto-send is earned per category and can be undone.

Your controls

  • Roles

    Owner, admin, agent and viewer, enforced the same way in the dashboard, the API and the Claude connector.

  • Audit log

    Every action by Hobson, your team or an API key is recorded, filterable by who did it and what.

  • Support access is opt-in

    Hobson staff can only see your workspace if you turn on support access in settings.

  • Export and deletion

    Export your data at any time. Deleting a workspace removes its data and files after a short grace period. Customer erasure requests are supported.

  • Retention

    Raw inbound email is deleted seven days after processing. You can set how long conversations are kept.

  • Sign-up and API protection

    Verified email and bot checks at sign-up, Cloudflare in front of the app, and rate limits on sign-in and the API.

Questions