Hang

Trust

Security & privacy.

Your customers’ data runs your business. Hang protects it with enterprise-grade controls, audited end to end — and never uses it for anything but your brand.

Certified & compliant.

Audited annually

SOC 2 Type II

AICPA SOC 2 certification mark

Independently audited for security, availability, and confidentiality controls.

ISO 27001

Certified information security management system meeting international standards.

GDPR

Compliant with the European Union's General Data Protection Regulation.

CCPA

Compliant with the California Consumer Privacy Act for data protection.

The controls

Security in every layer.

Encryption everywhere

AES-256TLS 1.3

All data is encrypted at rest with AES-256 and in transit with TLS 1.3 — customer profiles, order history, and every message in between.

Your data stays yours

No AI trainingFull ownership

You retain full ownership of your data. Hang never uses your customer data to train shared AI models or for any purpose other than running your brand’s experience.

Data isolation

Per-brand isolationAccess logged

Sensitive data is isolated per brand and inaccessible by default — access is role-based, multi-factor, reviewed regularly, and logged end to end.

Resilient infrastructure

Multi-regionAuto-failover

The platform runs on enterprise-grade cloud infrastructure with geographic redundancy, automatic failover, and continuous capacity monitoring.

99.9% uptime SLA

24/7 monitoring

We stand behind a 99.9% uptime service-level agreement, with real-time health monitoring and instant failover built into every service.

Continuous watch

Threat detection24/7 response

Automated security scanning, real-time threat detection, and an on-call security team watching around the clock.

The practice

How we operate.

Access control

Role-based access, multi-factor authentication, and regular access reviews. All access to production systems is logged and monitored.

Vendor security

Every third-party vendor is vetted against our security standards. Our infrastructure partners maintain SOC 2, ISO 27001, and other relevant certifications.

Incident response

A comprehensive incident response plan with defined procedures for detection, containment, eradication, and recovery — trained and drilled, ready 24/7.

Employee security

Background checks and security training for every employee, with regular refreshers and phishing simulations to keep the culture sharp.

Regular audits

Internal assessments plus third-party audits verify our controls. SOC 2 Type II and ISO 27001 certifications are maintained through annual audits.

Privacy

Your customers’ privacy, respected.

Data collectedOnly what the experience needs
Consumer rights (access, deletion)Honored per GDPR & CCPA
Data salesNever

Report a vulnerability

Security concerns, questions, or a vulnerability to report — our security team reads every message.

security@hang.com

Request documentation

Need our SOC 2 report, security questionnaire responses, or other documentation for a compliance review?

support@hang.com