For procurement, security, and legal reviewers.
FellowHire is built to SOC 2 and ISO 27001 standards, with formal certification in progress. Customer data is encrypted in transit and at rest. Model calls run through Amazon Bedrock inside our AWS environment and are never used to train models. Everything below is the longer version.
SOC 2
Certification in progress
ISO 27001
Certification in progress
AES-256
Encryption at rest
TLS 1.3
Encryption in transit
| Topic | FellowHire posture |
|---|---|
| Compliance frameworks | Built to SOC 2 and ISO 27001 standards (certification in progress) |
| Encryption in transit | TLS 1.3 |
| Encryption at rest | AES-256 |
| Hosting | AWS, US regions (EU on request) |
| Customer environment | Isolated AWS Enclave per customer |
| Model training on your data | Never |
| Model providers | OpenAI and Anthropic models via Amazon Bedrock, inside our AWS environment (no training) |
| Data residency | US default; EU available on request |
| Access controls | Role-based, scoped during fellow setup |
| Private network connections | Outbound split-tunnel VPN, customer-scoped routes |
| Desktop application access | Optional; runs on customer-provided Windows machines, scoped and logged |
| Audit logs | Yes, retained to SOC 2 standards |
| Customer data deletion | On request, or at end of engagement |
| DPA available | Yes |
| Sub-processors | Listed below |
When you bring on a fellow, you decide what your fellow can see. During setup, we scope which Slack channels, which Teams channels, which integrations, and which documents the fellow has access to. The fellow only operates within those scopes. You can revoke any scope at any time.
When the fellow does work, like drafting an email, summarizing a document, or running a competitor brief, the work happens in your isolated AWS Enclave. Data is encrypted in transit and at rest the whole way through.
When the fellow needs to call a model (OpenAI or Anthropic), the call runs through Amazon Bedrock inside FellowHire's AWS environment. Model calls never leave AWS. Bedrock does not use customer data to train models and does not share it with the model providers. Your data is not used to train their models. Ever. Full stop.
When the fellow integrates with another tool (HubSpot, Salesforce, Clio, Google Workspace, etc.), it uses OAuth scopes you approved during setup. You can revoke any integration at any time. Revoking a scope stops the fellow from using that scope on the next call.
When you end an engagement, customer data is deleted on request or at the end of the engagement per the DPA. Audit logs are retained to SOC 2 standards and then deleted.
Never train on your data.
No exceptions. Not for product improvement. Not for model fine-tuning. Not in aggregate. Not anonymized.
Never share your data with other customers.
Each customer runs in an isolated AWS Enclave. Your data does not commingle.
Never sell, rent, or expose your data to advertisers.
This is not an ad-funded business.
Never give your data to model providers for training.
Model calls run through Amazon Bedrock inside our AWS environment. Bedrock does not use customer data to train models and does not share it with OpenAI or Anthropic.
Never give the fellow access to scopes you did not approve.
If it was not connected during setup, the fellow cannot see it.
Never read customer data without an audit trail.
When FellowHire staff need to access customer data (rare, only with customer permission), it is logged and reviewable.
FellowHire is built to SOC 2 and ISO 27001 standards, and formal certification is in progress. Everything we have built — infrastructure, data handling, access controls, audit trails — is built to meet both standards. Customer data is encrypted in transit (TLS 1.3) and at rest (AES-256). OpenAI and Anthropic models run through Amazon Bedrock inside our AWS environment, and your data is never used to train models.
SOC 2
SOC 2 is the standard most US-based buyers ask for. Our controls are built to SOC 2 standards and cover security, availability, processing integrity, confidentiality, and privacy. Formal certification is in progress.
ISO 27001
ISO 27001 is the international standard for information security management systems. Our ISMS is built to the same posture as our SOC 2 program with the additional structure ISO 27001 requires. Formal certification is in progress.
Security Review
We share a security controls summary and our DPA under mutual NDA during procurement. To request, click below or email [email protected].
Request security review package →Encryption in transit.
All connections to and from FellowHire use TLS 1.3. This includes Slack, Teams, integrations, and model provider calls.
Encryption at rest.
All customer data at rest is encrypted with AES-256.
Hosting.
FellowHire runs on AWS in US regions by default. EU regions are available on request.
Customer isolation.
Each customer runs in an isolated AWS Enclave. There is no shared compute between customers. There is no shared storage between customers. Your fellow does not have access to anything outside your environment.
Sandboxed agent runtime.
Each fellow runs on FellowHire's agent runtime in a sandboxed environment, with only the integrations and access scopes you approved.
Fellows can optionally connect to your private network to work with on-premise and private cloud systems — file servers, self-hosted CRMs, internal databases, and intranet tools. This connectivity is designed to grant the minimum access required, under your control.
Outbound-only connection.
The fellow's environment establishes an outbound VPN client connection to the VPN server you already operate, using credentials you issue. You open no inbound firewall ports, and we install nothing on your servers.
Split tunneling with scoped routes.
Only the internal subnets you approve are routed through the tunnel. Everything else the fellow does stays on its normal path. The fellow can reach exactly what you scoped, and nothing more.
Split-DNS.
Internal hostnames resolve through your resolver, only for the search domains you configure. Your internal DNS is never exposed beyond the tunnel.
Multiple networks, independently scoped.
A fellow can hold connections to more than one private network — office, datacenter, private cloud — each configured and scoped separately.
Revocable at any time.
The connection uses credentials you control. Revoke them on your VPN server and the fellow's access ends immediately — no action from us required.
Optionally, a fellow can operate Windows desktop applications — including legacy line-of-business software with no API and no cloud version. This capability is designed the same way as everything else on this page: your hardware, your scoping, your logs, your kill switch.
Runs on your hardware, inside your network.
Desktop application access is installed on a Windows machine you provide, on your premises or in your private cloud. The fellow reaches it only over the private network connection described above. Your applications and their data stay on your machine.
Scoped to the applications you approve.
During setup, we scope which applications and which tasks the fellow can perform. The fellow operates within those scopes and nothing else — the same posture as every other integration.
Every action logged. Failures reported, not guessed through.
Every action the fellow takes in a desktop application is logged and reviewable. When a task cannot complete — for example, after an application update changes a screen — the fellow stops and reports exactly where, rather than guessing.
No shared automation clouds.
The work travels between your machine and the fellow's isolated environment over your private connection. Your screens and business data are never routed through shared robotic-process-automation platforms or third-party desktop-control services.
Revocable at any time.
Disconnect the machine, revoke the network credentials, or uninstall — any one of them ends access immediately, without any action from us.
Role-based access.
Customer access controls are role-based. Your team grants access to the fellow during setup. We do not have default access to your data.
FellowHire staff access.
Staff access to production systems is least-privilege, logged, and reviewed. Engineers do not access customer data without explicit customer permission and an audit trail.
Audit logs.
Every fellow action and every integration call is logged. Logs are retained to SOC 2 standards. Logs are available to you on request.
Revocation.
You can revoke any scope, any integration, or the entire fellow at any time from your workspace settings. Revocation takes effect on the next call.
Providers.
FellowHire uses OpenAI and Anthropic models, run through Amazon Bedrock inside FellowHire's AWS environment. Model calls never leave AWS.
No training on your data.
Customer prompts, customer data, and customer outputs are never used to train models. Amazon Bedrock does not use customer data to train models and does not share it with the model providers.
Provider data retention.
Model calls are processed by Amazon Bedrock inside our AWS environment. Bedrock does not retain customer prompts or outputs for training and does not share them with the model providers. Detail is available in our DPA.
Model output review.
Fellows draft and summarize. Where output is sensitive (legal documents, financial reports, customer-facing copy), our recommended workflow is human review before send. We do not market fellows as replacements for the human in the loop on high-stakes work.
Data residency. Customer data is stored in AWS US regions by default. EU residency is available on request for European customers and customers with regulatory requirements.
Sub-processors. The list below is current as of this page's last update. Updates are posted here and notified per DPA.
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Hosting and storage | US (or EU on request) |
| Amazon Web Services (Bedrock) | Model hosting — OpenAI and Anthropic models (no training) | US |
During engagement.
You can delete customer data from your workspace at any time. Audit logs are retained to SOC 2 standards.
End of engagement.
When an engagement ends, customer data is deleted within 30 days on request, or per the timeline in your DPA. Audit logs are retained to SOC 2 standards and then deleted.
Export.
You can request a full data export at any time. Format and timing are described in the DPA.
Data Processing Agreement. We provide a DPA with every annual engagement. Pilot agreements include a short-form data handling addendum. Full DPA is available on request before contract signature.
Custom DPA. For Scale-tier customers and customers with specific procurement requirements, we accept reasonable custom DPA edits. Reach out via the form below.
If you believe you have found a security vulnerability in FellowHire, email [email protected]. We respond within 1 business day. We do not pursue legal action against good-faith security researchers who follow responsible disclosure.
Our controls are built to SOC 2 standards. Formal certification is in progress. We share a security controls summary and our DPA under NDA during procurement.
Our controls are built to ISO 27001 standards. Formal certification is in progress. We share a security controls summary and our DPA under NDA during procurement.
AWS US regions by default. EU regions on request.
Never. OpenAI and Anthropic models run through Amazon Bedrock inside FellowHire's AWS environment. Bedrock does not use customer data to train models and does not share it with the model providers.
No. The fellow only operates within scopes you approved during setup. You can revoke any scope at any time.
Optionally, a fellow can connect to your private network over an outbound split-tunnel VPN using credentials you issue. Only the internal subnets you approve are routed through the tunnel, nothing is installed on your servers, no inbound firewall changes are needed, and revoking the credentials on your VPN server ends access immediately.
Yes, optionally. Desktop application access runs on a Windows machine you provide, inside your network, and lets the fellow operate the applications you approve — including legacy line-of-business software with no API or cloud version. The fellow works only the applications and tasks scoped during setup, every action is logged, and the work travels over your private connection to the fellow's isolated environment — never through shared automation clouds. Disconnecting the machine or uninstalling ends access immediately.
Yes. The DPA is provided with every annual engagement and is available on request during procurement.
Bring them to a 30-minute call with our team. We will go through your specific procurement and risk-management requirements together.