This page describes how Hexagon Labs, Inc. ("Hexagon") protects the data customers trust us with, how to tell us about a security problem, and which companies process customer data on our behalf. It is written for customers, their security teams and security researchers. For what data we collect and why, read the Privacy Policy; for the contract that governs use of the service, read the Terms of Service.
How customer data is protected
Hosting
Hexagon runs on DigitalOcean App Platform in the United States. Our database, authentication and file storage are managed services from Supabase. We do not operate our own data centers or physical servers.
Encryption
- All traffic between your browser or app and Hexagon, and between Hexagon and the providers listed below, is encrypted in transit with TLS.
- Data at rest is encrypted by our hosting and database providers, including database storage, file storage and backups.
- Payment card details are never stored by Hexagon. They are handled by our payment providers, which are PCI DSS compliant.
Access to systems
- Access to production systems follows least privilege: each person gets only the access their role needs, and access is reviewed when roles change and when someone leaves.
- Staff sign in to company systems with Google single sign-on, and multi-factor authentication is required.
- Provider credentials, API keys and webhook secrets are stored as environment secrets on the hosting platform, are used only server-side, and are not committed to source code.
Continuous monitoring and audit
- Our security controls are monitored continuously with Vanta, which checks our cloud accounts, identity provider, source code hosting and staff devices against our policies.
- Hexagon is undergoing a SOC 2 Type 1 and Type 2 audit with Sensiba LLP. Customers under NDA can ask for the report once it is issued by writing to [email protected].
- Application, server and database logs are forwarded to a central log platform where alerts are configured for errors and unusual activity.
- Dependencies are scanned for known vulnerabilities, and the source code is scanned for secrets and common security flaws on every change.
Responsible disclosure
If you believe you have found a security vulnerability in Hexagon, please email [email protected] with enough detail for us to reproduce it: the affected URL or component, the steps you took, and what you observed. We acknowledge every report within 2 business days and keep you informed while we investigate and fix the issue.
We do not run a paid bug bounty program. We are grateful for reports and are happy to credit researchers who want to be named once a fix has shipped.
Hexagon will not pursue legal action against researchers who act in good faith: who make a reasonable effort to avoid privacy violations, data destruction and service disruption, who only access the data needed to demonstrate the issue, and who give us a reasonable time to fix it before disclosing it publicly.
A machine-readable version of this contact information is published at /.well-known/security.txt.
Subprocessors
These companies process customer data on Hexagon's behalf. Each one is bound by contractual confidentiality and data protection obligations and may only use the data to provide its service to us. We update this list when a subprocessor is added or removed.
- DigitalOcean Application hosting, container registry and load balancing (United States)
- Supabase Managed Postgres database, authentication and file storage
- Google Workspace email, single sign-on and Google APIs connected by customers
- GitHub Source code hosting, code scanning and CI builds
- Anthropic Language model inference
- OpenAI Language model inference
- Meta WhatsApp Cloud API Sending and receiving WhatsApp messages for merchants
- Stripe Subscription billing and card payments
- dLocal Payments and payouts in Brazil
- Twilio Voice and SMS for customer support channels
- Resend Transactional email delivery
- Sendblue iMessage and SMS delivery
- Slack Internal alerts and customer support workspaces
- Better Stack Log storage, uptime monitoring and alerting