Hyvop Community Edition Release 2026|Get informed when it's available →
Security & Governance

Built for governance. Designed for security.

Hyvop works inside your existing boundaries. No new attack surface. Self-hosted, or single-tenant managed in your region.

Pre-launch. This is our security model and roadmap; SOC 2 is in progress, not complete.

The agent never acts alone.

RoleResponsibilityCan execute?
OwnerDecides the action (delete, resize, keep)No
ManagerApproves or rejects the Owner's decisionNo
Hyvop AgentExecutes the approved action via cloud APIYes, only after approval

Every decision is logged with who approved, when, from which IP, and why.

What we never do

We neverInstead, we
Read data inside your databases, storage, or workloadsProcess resource metadata, tags, and cost figures only
Store long-term cloud credentialsUse scoped, least-privilege IAM roles you create and control
Act autonomously on destructive changesRequire explicit confirmation and approval
Co-mingle your data with other customersRun isolated, single-tenant processing
Retain your data indefinitelyGive you full control of retention

Your data stays yours.

What data do you access? Resource metadata, tags and cost figures. Nothing inside your resources.

Do you read workload or customer data? Never.

Where is data processed? In your self-hosted deployment, or a single-tenant Hyvop Cloud instance in your region.

How long is data retained? You control retention entirely.

What about the LLM assistant and NLP dashboards? The LLM runs on your own keys inside your deployment. Nothing is exported.

No new user database.

Hyvop plugs into your identity provider. Role-based access, no new user database.

Identity providerStatus
Okta (SCIM + SAML)Planned for launch
Microsoft Entra ID (Azure AD)Planned for launch
Google WorkspaceOn the roadmap

Cloud integrations by design

CloudIntegration methodPermission scope
AWS (first)IAM Role (cross-account)Read-only metadata and cost; write limited to specific remediation actions
Azure (roadmap)Service Principal with custom roleRead-only Resource Graph and Cost Management; write scoped to resource groups
GCP (roadmap)Service Account with predefined rolesRead-only Asset Inventory and Billing; write scoped to specific projects
VMware / OpenShift (roadmap)API token with read-only scopesInventory and performance metrics; write via controlled workflows

Every remediation leaves a trail.

  • • Who initiated the detection
  • • Who was identified as Owner, Manager, and Operator
  • • The exact conversation and approval
  • • Who approved, when, and from which IP
  • • The cloud API call and its result
  • • Full before/after state

Exportable to your SIEM or audit tools.

Foundations, not afterthoughts.

  • • All data encrypted in transit (TLS 1.3) and at rest (AES-256)
  • • Single-tenant, isolated processing, you host it
  • • Third-party penetration testing planned ahead of general availability
  • • SOC 2 Type II program planned
  • • GDPR-aligned data handling