Hush AI

Security & Trust

This page describes, truthfully and specifically, how Hush AI handles your data today. Every claim is testable. If any claim is vague or untrue, challenge us at [email protected]. Prefer to test rather than read? The verify-us page has copy-paste terminal checks and the public registers.

In one line: we keep no conversations or documents. We process what you send, then it is gone, so there is no conversation or document stored to leak, sell, or be compelled to hand over. The only thing kept is the chat history you choose to save, encrypted on your own device, never on our servers, and gone the instant you delete it.

The question Big Tech could not answer. In June 2025, Microsoft France's director of public and legal affairs was asked at a French Senate hearing, under oath, whether he could guarantee that data held for French citizens would never be passed to US authorities. His answer: "No, I cannot guarantee it." Under the US CLOUD Act a US-owned provider can be compelled to hand over data wherever it is stored. Microsoft says this has never happened; the point is that they could not promise it would not. Hush runs on hardware we own, with no US parent and no third-party AI in the chain, so that question does not arise here. Read what was said.

ICO Data Controller Registration: ZC126901

Our role: Data Controller and Data Processor

Hush AI is registered with the UK Information Commissioner's Office as a data controller for the personal data we collect to operate the service (your account details, usage logs). For the content you submit through the service (your prompts and the AI responses), your organisation is the data controller and Hush AI acts as a data processor on your instructions. This distinction is documented in our Data Processing Agreement, which every business customer signs before live data flows.

Architecture, how Hush AI is actually built

Customer requests pass through three layers, all physically located in the United Kingdom:

Hush Refinery, the physical facility in the United Kingdom where inference hardware lives. Nothing about your request ever leaves this facility's network.

Hush Gateway, the software front door. Every request passes through it: it validates your identity, enforces your plan's quota, logs metadata, strips any internal reasoning tokens, and routes it to the right model.

Hush Models, Omega, Prism and Lambda (a fourth, Alpha, is temporarily out of service while we fix a routing fault). Each runs on dedicated hardware and processes your request in memory; your content is processed in memory and not persisted to our storage. Your web-chat history is saved encrypted on your own device so you can return to it, and is deleted the moment you delete it; API requests are not stored at all. Only request metadata is logged (see Data retention below).

Hush Services, Hush Cyclops Vision (document extraction and OCR with automatic secure wipe), Hush Echo (audio transcription with burn-after-reading), and a privacy-first search engine. All follow the same design: process, then securely wipe on completion.

Where your data is processed

Every query sent to Hush AI is processed on hardware physically located in the United Kingdom. The inference cluster consists of dedicated NVIDIA and AMD hardware connected over a private link. No part of your request is sent to any cloud provider or third-party AI service.

The web front-end (hush-ai.uk) sits behind Cloudflare for edge TLS and DDoS protection, so requests pass through Cloudflare's edge, where it handles connection metadata (IP, timestamp, URL). Cloudflare is not an AI sub-processor, is never sent your saved conversations or documents, and never uses anything for training. Your prompts and responses are neither stored by Cloudflare nor sent to any AI service other than our own hardware.

EU & EEA customers

Hush AI operates entirely within the United Kingdom. Under the European Commission's adequacy decisions for the UK (renewed 19 December 2025, valid until 27 December 2031), EEA-based organisations may share personal data with Hush AI without Standard Contractual Clauses or any additional GDPR transfer mechanism.

For non-UK, non-EEA customers (including Brazil and other jurisdictions), the Data Processing Agreement's International Transfer Addendum applies, shifting responsibility for lawful basis under local law to the customer as controller.

Sub-processor list

No third party ever stores your prompt or response content, or uses it for AI or training. Two third parties process limited personal data to run the service, and we disclose them plainly:

Sub-processorPurposePersonal data processedPrompt/response content?
Stripe Payments UK LtdPayment processingName, email, payment card details (held by Stripe, never by us)Never
CloudflareEdge TLS, DDoS protectionIP address, request metadata (timestamp, URL)Passes through the edge in transit only; never stored, never used for AI or training

All AI inference, storage, and processing of your content happens exclusively on hardware we own in the United Kingdom. No cloud AI provider, no third-party model API, no analytics service. Spot an error on this page? Tell us at [email protected] and we will correct it.

What we log, locally

For every API request, we record the following on local UK storage:

We do not store the content of your prompts, responses, or web-chat conversations, metadata only, as listed above. Nothing you send is ever used for training or analysed for marketing. The database schema is open and can be inspected during a pilot.

Your right to audit

Every account includes a one-click export of your organisation's full audit trail (CSV or JSON), every request, timestamped, metadata only, downloadable any time you are signed in, at /api/audit/export.csv or /api/audit/export.json, no need to ask us. It is your IG evidence pack, yours to keep, during and after any pilot. For the full due-diligence picture, including what we have not certified yet, see Procurement & due diligence.

Authentication & access

Data retention summary

Incident response

We maintain a written Incident Response Plan covering detection, containment, investigation, ICO notification within 72 hours as required by GDPR Article 33, and customer notification within 48 hours. A summary is available on request.

What is live today Live

What we are working on In progress

Cyber Essentials certification, UK National Cyber Security Centre accreditation. Application in preparation.

Cyber insurance, quotes in progress with UK specialist insurers.

NHS Data Security and Protection Toolkit (DSPT), to be completed at the point of first NHS trust engagement.

Where to draw the line

Hush AI is, today, a small private company. It has not undergone ISO 27001 certification. It does not have a SOC 2 Type II report. It does not have a 24/7 security operations centre. If your procurement process requires any of those as a mandatory condition, Hush AI is not the right partner for you yet, and we will tell you honestly where we are on the roadmap to each.

What we offer instead is full transparency, a free trial, and the right to walk away at any time with every log entry we hold on you.

For IG teams and Data Protection Officers

The following documents are available free of charge to any prospective customer's IG officer or DPO. Email [email protected] and we respond within two working days.

Free: a plain-English guide to private AI

Vendor-neutral, reviewed against GDPR. What to ask any AI tool before you trust it with anything private, and how to tell what it really keeps.

Get the templates, free →

No email, no sign-up. Download them straight from our resources page, and we keep no conversations or documents.

Security questions, audit requests, or vulnerability reports

We respond to every legitimate enquiry within two working days.

[email protected]

Hush AI is a drafting and summarisation assistant. It is not a source of medical, legal, or financial advice. Always verify AI-generated outputs before acting on them.

Hush AI is founded and led by Dr W.J Carter.
← Back to Hush AI

Frequently asked questions

Where is my data stored with Hush AI?

On your own device. Conversation history is stored encrypted there until you delete it, never on our servers, and is never used to train models.

Does my data go through Big Tech (OpenAI, Google, Microsoft)?

No. Hush runs its own models on its own hardware, with no third-party AI API in the chain, so your content never passes through a Big Tech system. And because we store none of your conversations or documents, there is nothing for anyone to be compelled to hand over.

Does Hush AI use my conversations for training?

No. Your content is never used to train models and is never analysed for marketing. We do not store the content of your API requests; your web-chat history is stored encrypted locally on your own device until you delete it, and only request metadata is logged.

Can I get an audit trail for my information-governance lead?

Yes. You can export an audit log of your usage in one click, in CSV or JSON, your own GDPR Article 30 / IG evidence pack, yours to keep.

You are a new company. Should I trust you with sensitive data?

A fair challenge, and you should not have to take our word for it. Everything on this page is checkable: the company at Companies House (17278687), our data-protection registration at the ICO (ZC126901), and the privacy claims themselves in the product, because there is no conversation or document stored on our servers to leak or hand over. Because we are early you would be among our first, so rather than another organisation's assurances the free two-week pilot leaves your IG lead a report from your own audit log, verifiable against your own work. Every trusted supplier had a first customer, and we would rather earn yours on evidence you can check than on a testimonial you cannot.

See the full Trust Centre →
How this lands in practice: private AI for solicitors · secure AI for GPs · confidential transcription · NDA and contract review