# Secure, permission-aware AI workspace for teams.

Canonical: https://usehai.ai/security

Markdown: /security.md

Description: Hai is designed for permission-scoped integrations, auditability, GDPR-aligned workflows, and a SOC 2 and ISO 27001 roadmap.

Page: Hai security overview.

For: Companies that need AI work to stay scoped, reviewable, and controlled.

Hai can: Support permission-scoped integrations, approval controls, auditability, and protected company context.

Hai is designed for companies that need connected AI work to stay scoped, reviewable, and controlled.

## Security Areas

- **Permission scopes:** Agents work within explicit scopes so each workflow can be limited to the systems, data, and actions it actually needs.
- **Integration access:** Connected tools are treated as governed workspace resources, with visibility into where context and actions are used.
- **Approval controls:** Sensitive work can be prepared by agents while execution waits for a human approval step.
- **Auditability:** Important workspace activity is designed to leave an audit trail for review and operational accountability.
- **Data protection:** Hai is designed around encrypted transport and storage for company context and workspace artifacts.
- **Compliance roadmap:** Hai is designed to support GDPR-aligned workflows. Hai is pursuing SOC 2 and ISO/IEC 27001 as part of its security roadmap.

## Controls

- The public site uses cautious security copy until formal certifications are complete.
- Permission-scoped integrations.
- Audit trail for important work.
- GDPR-aligned, SOC 2 and ISO 27001 in progress.
