Security, privacy & compliance
Member trust is the precondition for every program.
Hume is built so people scan honestly and businesses still get the insight they need, with clear boundaries between the two.
Controls
What we put in place.
Encryption everywhere
Data is encrypted in transit with TLS and at rest with AES-256. Keys are managed and rotated by our cloud provider's KMS.
Least-privilege access
Role-based access in Hume Connect for admins, clinicians, and coaches, so people only see the members assigned to them.
Consent-first sharing
Members choose what is shared. A team only sees results for the people who have opted into their program.
Data residency
EU and US hosting regions are available so data stays in the jurisdiction your program requires.
Retention controls
Configurable retention windows, member-initiated deletion, and documented deletion SLAs for offboarding.
Vendor management
Subprocessors are reviewed before onboarding, and the current list is available to customers on request.
Compliance
Programs we support.
HIPAA-compliant
Member data is encrypted end to end and stored on HIPAA-compliant servers; BAA available.
GDPR
DPA, EU residency, and data subject request workflows.
SOC 2 program
Ongoing controls program with independent review.
Member ownership
Data is never sold, and is shared only with providers the member authorises.
Compliance posture varies by deployment and contract. Ask our team for the current documentation set covering your program before making regulatory commitments.
FAQ
Common security questions.
Does Hume sign a Business Associate Agreement (BAA)?
For programs where Hume handles protected health information on behalf of a covered entity, a BAA can be executed as part of contracting. Contact our team to start that review.
How does Hume support GDPR obligations?
Hume supports data subject access, correction, and deletion requests, offers EU data residency, and can provide a Data Processing Addendum during contracting.
What does an employer actually see?
Employers and plan sponsors see only what the member has consented to share for the program, and reporting is set up during onboarding. Individual results stay with the member and the clinicians the member has authorized.
How do teams sign in to Hume Connect?
Hume Connect uses its own accounts with email-based sign-in and role-based permissions. Single sign-on, an API, and data export are not available today.
How do we report a security issue?
Send details through the contact form and mark the topic as partners or research; security reports are routed to our engineering team for triage.