Security at Humalike

Last updated: August 27, 2026

Soofte, Inc. (d/b/a “Humalike AI”) provides behavioral infrastructure for humanlike AI. Businesses trust our APIs inside their products, so we treat the security of their data as a core part of the product.

Infrastructure

Our platform runs on Amazon Web Services (AWS), hosted in Europe. We use AWS managed services — including RDS, S3, and VPC network isolation — and AWS is responsible for the physical security of its data centers. Soofte, Inc. is a Delaware corporation; our team operates from Spain and our platform data is hosted in the EU.

Encryption

  • In transit: all traffic to and between our services is encrypted with TLS (HTTPS only).
  • At rest: customer data in our databases and object storage is encrypted at rest using AWS-managed encryption (AES-256).
  • Payments: billing is handled by Stripe, a PCI-DSS certified provider. We never store card details on our systems.

Access control

Access to production systems follows the principle of least privilege and is limited to the small set of engineers who need it. Identity is centralized in Google Workspace with multi-factor authentication required on company accounts, and credentials and application secrets are managed in dedicated tooling (1Password, Doppler) — never in code. Access is reviewed when roles change and when people leave.

Monitoring and availability

We monitor our infrastructure and application health continuously (AWS CloudWatch, Better Stack) and alert our engineers when something looks wrong. Current and historical availability is published on our public status page.

Compliance

We are implementing an information security management system aligned with ISO/IEC 27001:2022, with certification targeted for Q4 2026. We are not yet certified. We operate in accordance with the GDPR.

Responsible disclosure

If you believe you have found a security vulnerability in our services, please email security@humalike.ai. Include enough detail for us to reproduce the issue. We will acknowledge your report, investigate, and keep you informed. We ask that you do not access or modify other customers’ data and that you give us reasonable time to remediate before public disclosure.

Questions?

Security questions from customers and prospects: security@humalike.ai.

Adapted from Basecamp’s open-source policies (github.com/basecamp/policies), CC BY 4.0.