FounderHub builds and operates AI and automation for real businesses, so how those systems are controlled matters as much as what they do. This page sets out the principles we work to. It describes our approach, not a certification claim.
Governed execution
Automated and AI assisted actions run inside defined controls rather than acting freely. Work is scoped, and higher risk actions are constrained by policy.
Identity and authority checks
Actions are tied to an identity and to the authority that identity holds. Requests without the required authority are refused rather than assumed.
Human approval where required
Actions that create external effect, spend, or change important records require human approval before they proceed. The default position is to prepare and propose, not to act unattended.
Evidence and auditability
Significant actions produce an append only record so that what happened, and on whose authority, can be reviewed after the fact.
Least privilege
Systems and people are given the minimum access needed for the task, and access is separated by tenant and by role.
Secure development practices
Changes are version controlled, reviewed and tested before release. Security relevant behaviour is covered by tests where practical.
Data minimisation
We collect only the information needed for the purpose, and we avoid moving sensitive content into places it does not need to be, including analytics.
Separation of research from production claims
Research and private development are kept clearly separate from what we present as available. Product maturity is stated honestly across the site.
Responsible AI deployment
AI is deployed with defined scope, human oversight and the ability to refuse or escalate rather than guess when confidence is low.
Confidential handling of business information
Information shared during applications, reviews and engagements is treated as confidential and handled under appropriate agreements.
What we do not claim
We do not claim ISO 27001, SOC 2, Cyber Essentials, HIPAA compliance, formal certification, independent penetration testing or third party assurance on this page. Where a specific engagement requires any of these, it is addressed directly with the client. See our privacy notice for data protection detail.