Security

Effective 30 August 2026

Hosho reviews prompts - which means we hold text that is often close to the heart of how a company's product works. This page says plainly what happens to it, who can reach it, and what we do not do with it. Where a statement is a legal commitment it is quoted from our Privacy Statement.

What we do not do with your prompts

From our Privacy Statement, verbatim: we do not sell your data, share it between customers, use it to train AI models, or use it for advertising. Running a review does send your prompt text to third-party AI providers, under their own API terms and solely to generate your review.

Who processes it

The AI providers currently include Anthropic and Google, and models reached through OpenRouter (an aggregator that routes to further providers, such as Z.ai). We change providers and models over time as we tune quality, cost, and availability. The Service runs on Supabase (database and sign-in), Vercel (hosting and cookieless site analytics), Render (hosting), and Google (sign-in). Your data is stored and processed primarily in the United States.

Who can see your workspace

Access is decided by workspace membership, not by who managed to sign in. Anyone with a Google account can authenticate; what they can then see is governed by an explicit membership record mapping an email address, or a whole company domain, to one workspace. A signed-in person with no membership sees nothing at all - not an empty version of someone else's workspace, but no customer data whatsoever. Every data route and every page re-checks this server-side and fails closed, so a missing or unreadable membership denies access rather than granting it. Whole-domain grants reject public email providers, so no one can claim a workspace by signing up with a consumer address.

API keys

Keys for the MCP server and the Git Action are minted per person and shown once. We store them to validate requests; our own operator tools display only a one-way fingerprint, never the key, so a key cannot be recovered from a screen or a screenshot. Disabling a key takes effect on its next request, with no cache to wait out. If a key is exposed, tell us or disable it yourself and mint a new one - we never re-enable an exposed key.

What our automation sends

The Git Action reports counts about each run - how many files it reviewed, skipped, or suppressed - so we can measure the service. Those reports carry no prompt content, no diffs, and no file bodies. The prompt text itself is sent only when you ask for a review of it.

Deleting your data

From Settings you can delete a workspace, all of your organisation's data, or your whole account, at any time, without asking us. Deleting a workspace or your organisation's data removes that content from our live systems. Deleting your account removes your personal data and access, and anonymises your email address on work your team keeps. Backups age out on their normal cycle. Deleting an organisation also disables its API keys.

What we do not have yet

Hosho is an early-stage product and we would rather you hear this from us than discover it in a questionnaire: we do not hold a SOC 2 or ISO 27001 certification, we do not publish a third-party penetration test, and we do not offer a contractual uptime SLA. If your procurement needs any of these, email otto@hoshoai.com and we will tell you honestly where we are and what we can commit to.

Reporting a vulnerability

Email otto@hoshoai.com with what you found and how to reproduce it. We will confirm receipt, keep you updated while we fix it, and credit you if you would like us to. Please do not run automated scans against production or access data that is not yours.