Transparency
We don't ask you to trust us. Every claim below links to a third-party verification tool. Click it. Check it. If anything on this page is wrong, email [email protected] and we will correct it or remove it.
Identity - who we are
Hush AI Limited is registered in England & Wales, company number 17278687. It is a UK entity with no US parent company, no US subsidiary, and no US beneficial owner.
Registered with the UK Information Commissioner's Office, registration number ZC126901. This is a legal requirement for any UK organisation processing personal data.
Infrastructure - where your data goes
Every AI model runs on dedicated hardware physically located in the United Kingdom, privately owned. No cloud GPU provider, no AWS, no Azure, no GCP. Your prompts and responses never leave hardware under our physical control.
You can verify this structurally: our sub-processor list names only Stripe (payments) and Cloudflare (DDoS/TLS). On the sealed lanes below Cloudflare relays ciphertext it cannot open; see Sealed transport. No cloud AI provider appears because none is used. This is published in our Security & Trust page, our Privacy Policy, and our Data Processing Agreement - all legally binding documents.
The US CLOUD Act compels US companies to hand over data stored anywhere in the world. It applies to AWS, Azure, GCP, OpenAI, Anthropic, Google, and Microsoft - regardless of which data centre region you choose. Hush AI is a UK company with no US parent entity and no US cloud sub-processor that stores your content. The Act has no legal mechanism to reach us.
Verify: check our Companies House filing (above) for ownership structure. Check our sub-processor list for the absence of any US cloud AI provider. Read our CLOUD Act explainer for the legal detail.
Transport security - your connection
All connections to hush-ai.uk are encrypted with TLS 1.2 or 1.3. HTTP Strict Transport Security is enforced with preload, meaning browsers will refuse to connect over plain HTTP even if someone tries to intercept the connection.
Every response from hush-ai.uk includes Content Security Policy, X-Frame-Options, X-Content-Type-Options, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, Referrer-Policy, and Permissions-Policy headers.
Our domain enforces DMARC p=reject, meaning any email claiming to come from hush-ai.uk that fails authentication is rejected outright - not quarantined, rejected. Combined with SPF, DKIM, and DNSSEC, this prevents domain impersonation.
TLS ends at Cloudflare, so on an ordinary website the edge could read what you send. On Hush's content lanes it cannot: your browser encrypts the request to a key that exists only on hardware we own (hybrid P-256 + ML-KEM-768, post-quantum required, AES-256-GCM, replay-guarded), we decrypt it on our machines, and the reply travels back the same way. Plaintext on these lanes is refused (HTTP 426), so a browser can never quietly fall back.
Sealed today: the homepage chat, sign-in, sign-up and password changes, the contact form, every PDF tool upload and download, document OCR, and every call the Forms, Review, Data and Meet apps make. The plain API endpoint /v1/chat/completions still accepts plaintext for SDK compatibility and is scheduled to become sealed-only; API customers who want the guarantee today use the sealed endpoint with the published client.
How you check it: the sealing key we serve is signed by a long-term key whose fingerprint is pinned inside the published browser code; the code is served with integrity hashes; and an hourly audit, run both directly and from an outside vantage through Tor, compares what the edge serves against the published copies. A swapped key or altered script is detected, not trusted. Still visible to the edge: page HTML, your session cookie and job-progress status messages (no document content). We say so because "nobody can read it" has to be literally true where we say it.
Data handling - what we log and what we don't
Prompt and response content is processed in memory and discarded. Only request metadata is logged, and the exact fields are listed in full below. Conversation history is stored encrypted on your own device, not on our servers.
This is not just a promise. It is a contractual obligation in our Terms of Service, Privacy Policy, and Data Processing Agreement. Breach of contract is enforceable in UK courts.
For every request, we log: timestamp (UTC), API key ID (not the full key), model used, prompt and completion token counts, HTTP status, latency, and endpoint called. This is the complete list. Every customer can export their own audit trail at any time.
Authentication and access control
Passwords are hashed with PBKDF2-HMAC-SHA256 at 600,000 iterations with unique salts, meeting the current OWASP recommendation for PBKDF2-HMAC-SHA256. New passwords are checked against the Have I Been Pwned database and rejected if they appear in known breaches. Two-factor authentication (TOTP) is available for all accounts.
What we do not have yet
Transparency means telling you what we haven't done, not just what we have. Other vendors bury this. We put it on the page.
We operate to the Cyber Essentials framework controls today. Certification application is in preparation. We will update this page when we hold the certificate.
We do not hold ISO 27001 or SOC 2 Type II certification. These require significant investment and audit infrastructure that a bootstrapped company cannot yet justify. If your procurement process requires either as a mandatory condition, we will tell you honestly rather than pretend.
NHS Data Security and Protection Toolkit completion is planned for the point of first NHS trust engagement. We will not claim DSPT compliance before we hold it.
Hush AI vs cloud AI providers
| Hush AI | ChatGPT / OpenAI | Microsoft Copilot | Google Gemini | |
|---|---|---|---|---|
| UK-owned company | Yes | No (US) | No (US) | No (US) |
| Privately owned hardware | Yes | No | No | No |
| CLOUD Act immune | Yes | No | No | No |
| Zero cloud AI sub-processors | Yes | N/A | N/A | N/A |
| ICO registered | ZC126901 | Varies | Varies | Varies |
| Never trains on your data | Contractual | Enterprise only | Enterprise only | Enterprise only |
How to challenge us
If you believe any claim on this page is false, misleading, or unverifiable:
- Email [email protected] with the specific claim
- We will respond within two working days
- If the claim is wrong, we will correct or remove it and publish the correction
- If we cannot prove a claim to your satisfaction, we will remove it from this page
Questions, challenges, or audit requests
We respond to every legitimate enquiry within two working days.
[email protected]Hush AI is a drafting and summarisation assistant. It is not a source of medical, legal, or financial advice. Always verify AI-generated outputs before acting on them.
← Back to Hush AIConvinced? The product will finish the job.
Start free pilot →Free for two weeks because the product is our only salesman.