Trust Center
Don't trust us. Verify us.
Hunta's whole thesis is proof over promises. This page says exactly what we do and don't have, and how to check the claims yourself.
What you can verify yourself, today.
- Isolation: every tenant can run
verify_isolationfrom their own console or API and receive an attestation: a machine-checkable statement that your data is isolated to your tenant, signed with Ed25519 so you can verify it against our published keys (JWKS atmcp.hunta.ai/.well-known/jwks.json). How it works → - The write path: every memory write is reviewed before it enters shared memory. The agent that proposes a write never approves its own write. The design →
- Your bill: usage is metered in deterministic token counts you can reproduce with a public tokenizer.
Architecture. isolated schemas + FORCE row-level security (row-level security that applies even to the table owner, not just client roles) · scoped API keys ("agent keys" can propose memory writes but cannot approve them or change settings) · noindexed, session-gated console · secrets held in a vault, never in code.
What we don't have (yet). No SOC 2 or ISO 27001 certification. We are an early-stage service and won't claim badges we haven't earned. No formal SLA on self-serve tiers. Penetration testing to date is first-party (including published prompt-injection results).
Subprocessors. Stripe · Cloudflare · Neon · Contabo · Lago (self-hosted) · emailit · GitHub/Google (sign-in). Details in the Privacy Policy.
Reporting a vulnerability. Good-faith research is welcome. Email [email protected]. We acknowledge within 72 hours, won't pursue good-faith researchers, and will credit fixes if you want credit.