Security
Security at Homefield
Homefield builds AI systems that work inside our customers' go-to-market and knowledge workflows. That means handling data our customers depend on, and designing for it from the start.
Compliance status
Homefield is currently engaging an independent CPA firm for a SOC 2 examination against the Security Trust Services Criteria. Our control environment is implemented and monitored continuously. Once the report is issued, we will make it available under NDA on request.
How we protect your data
Encryption. Customer data is encrypted both in transit and while stored. Credentials and API keys are held in a managed secrets store, never committed to code.
Access. Permissions are granted according to what a person's role actually requires, and nothing more. Privileged access to production requires multi-factor authentication. We review who has access to what on a recurring schedule, and remove access promptly when someone's role changes or ends.
Changes to production. Code and infrastructure changes go through version control and review before they ship.
Visibility. We keep audit logs of activity in our production environment and watch them for unexpected behavior.
Incidents. We keep an incident response plan that defines who does what, how severity is judged, and how we conduct review afterwards. It is reviewed annually.
People. Everyone at Homefield passes a background check, signs confidentiality and invention assignment agreements, and completes security training when they join and every year after.
Suppliers. We assess the security of vendors before we engage them and revisit that assessment periodically. Any vendor that touches customer data is contractually bound to protect it.
Customer data and AI
We do not use customer data to train our models, and we do not permit our model providers to use customer data to train theirs.
Customer data is used for one purpose only: delivering the service to the customer it came from.
Program ownership
Responsibility for security sits with the executive team. The Chief Executive Officer is the officer accountable for our information security and privacy program. The Board of Directors treats security, risk, and compliance as a standing item at every regular meeting and approves our security policies annually.
We maintain documented policies covering access control, cryptography, asset management, operations security, incident response, business continuity, third-party management, human resource security, and risk management. Every policy is reviewed at least once a year.
Security documentation
If you are evaluating Homefield or already working with us and need security documentation — a completed questionnaire, or our SOC 2 report once issued — write to security@homefield.so.
Reporting a vulnerability
Found something? Email security@homefield.so.
Please give us a fair chance to investigate and fix the issue before you disclose it publicly, and please don't access, change, or delete anyone else's data while you're looking. We won't pursue legal action against researchers who report in good faith and follow this guidance.