Hush AI

Transparency

We don't ask you to trust us. Every claim below links to a third-party verification tool. Click it. Check it. If anything on this page is wrong, email [email protected] and we will correct it or remove it.

Identity - who we are

UK-registered limited company
Verifiable

Hush AI Limited is registered in England & Wales, company number 17278687. It is a UK entity with no US parent company, no US subsidiary, and no US beneficial owner.

ICO-registered data controller
Verifiable

Registered with the UK Information Commissioner's Office, registration number ZC126901. This is a legal requirement for any UK organisation processing personal data.

Infrastructure - where your data goes

All AI inference runs on privately owned UK hardware
Verifiable

Every AI model runs on dedicated hardware physically located in the United Kingdom, privately owned. No cloud GPU provider, no AWS, no Azure, no GCP. Your prompts and responses never leave hardware under our physical control.

You can verify this structurally: our sub-processor list names only Stripe (payments) and Cloudflare (DDoS/TLS). On the sealed lanes below Cloudflare relays ciphertext it cannot open; see Sealed transport. No cloud AI provider appears because none is used. This is published in our Security & Trust page, our Privacy Policy, and our Data Processing Agreement - all legally binding documents.

Structurally immune to the US CLOUD Act
Verifiable

The US CLOUD Act compels US companies to hand over data stored anywhere in the world. It applies to AWS, Azure, GCP, OpenAI, Anthropic, Google, and Microsoft - regardless of which data centre region you choose. Hush AI is a UK company with no US parent entity and no US cloud sub-processor that stores your content. The Act has no legal mechanism to reach us.

Verify: check our Companies House filing (above) for ownership structure. Check our sub-processor list for the absence of any US cloud AI provider. Read our CLOUD Act explainer for the legal detail.

Transport security - your connection

TLS 1.2 / 1.3 encryption with HSTS preload
Verifiable

All connections to hush-ai.uk are encrypted with TLS 1.2 or 1.3. HTTP Strict Transport Security is enforced with preload, meaning browsers will refuse to connect over plain HTTP even if someone tries to intercept the connection.

Security headers (CSP, X-Frame-Options, COOP, CORP, Referrer-Policy)
Verifiable

Every response from hush-ai.uk includes Content Security Policy, X-Frame-Options, X-Content-Type-Options, Cross-Origin-Opener-Policy, Cross-Origin-Resource-Policy, Referrer-Policy, and Permissions-Policy headers.

Email anti-spoofing: SPF + DKIM + DMARC reject + DNSSEC
Verifiable

Our domain enforces DMARC p=reject, meaning any email claiming to come from hush-ai.uk that fails authentication is rejected outright - not quarantined, rejected. Combined with SPF, DKIM, and DNSSEC, this prevents domain impersonation.

Sealed transport: Cloudflare carries only ciphertext on the lanes that carry your content
Verifiable

TLS ends at Cloudflare, so on an ordinary website the edge could read what you send. On Hush's content lanes it cannot: your browser encrypts the request to a key that exists only on hardware we own (hybrid P-256 + ML-KEM-768, post-quantum required, AES-256-GCM, replay-guarded), we decrypt it on our machines, and the reply travels back the same way. Plaintext on these lanes is refused (HTTP 426), so a browser can never quietly fall back.

Sealed today: the homepage chat, sign-in, sign-up and password changes, the contact form, every PDF tool upload and download, document OCR, and every call the Forms, Review, Data and Meet apps make. The plain API endpoint /v1/chat/completions still accepts plaintext for SDK compatibility and is scheduled to become sealed-only; API customers who want the guarantee today use the sealed endpoint with the published client.

How you check it: the sealing key we serve is signed by a long-term key whose fingerprint is pinned inside the published browser code; the code is served with integrity hashes; and an hourly audit, run both directly and from an outside vantage through Tor, compares what the edge serves against the published copies. A swapped key or altered script is detected, not trusted. Still visible to the edge: page HTML, your session cookie and job-progress status messages (no document content). We say so because "nobody can read it" has to be literally true where we say it.

Data handling - what we log and what we don't

We never log, store, or train on your prompts or AI responses
Contractual

Prompt and response content is processed in memory and discarded. Only request metadata is logged, and the exact fields are listed in full below. Conversation history is stored encrypted on your own device, not on our servers.

This is not just a promise. It is a contractual obligation in our Terms of Service, Privacy Policy, and Data Processing Agreement. Breach of contract is enforceable in UK courts.

What we do log (metadata only)
Documented

For every request, we log: timestamp (UTC), API key ID (not the full key), model used, prompt and completion token counts, HTTP status, latency, and endpoint called. This is the complete list. Every customer can export their own audit trail at any time.

Authentication and access control

PBKDF2 password hashing (600K iterations) + breach checking
Live

Passwords are hashed with PBKDF2-HMAC-SHA256 at 600,000 iterations with unique salts, meeting the current OWASP recommendation for PBKDF2-HMAC-SHA256. New passwords are checked against the Have I Been Pwned database and rejected if they appear in known breaches. Two-factor authentication (TOTP) is available for all accounts.

What we do not have yet

Transparency means telling you what we haven't done, not just what we have. Other vendors bury this. We put it on the page.

Cyber Essentials certification
In progress

We operate to the Cyber Essentials framework controls today. Certification application is in preparation. We will update this page when we hold the certificate.

ISO 27001 / SOC 2
Not yet

We do not hold ISO 27001 or SOC 2 Type II certification. These require significant investment and audit infrastructure that a bootstrapped company cannot yet justify. If your procurement process requires either as a mandatory condition, we will tell you honestly rather than pretend.

NHS DSPT
Planned

NHS Data Security and Protection Toolkit completion is planned for the point of first NHS trust engagement. We will not claim DSPT compliance before we hold it.

Hush AI vs cloud AI providers

Hush AIChatGPT / OpenAIMicrosoft CopilotGoogle Gemini
UK-owned companyYesNo (US)No (US)No (US)
Privately owned hardwareYesNoNoNo
CLOUD Act immuneYesNoNoNo
Zero cloud AI sub-processorsYesN/AN/AN/A
ICO registeredZC126901VariesVariesVaries
Never trains on your dataContractualEnterprise onlyEnterprise onlyEnterprise only

How to challenge us

If you believe any claim on this page is false, misleading, or unverifiable:

  1. Email [email protected] with the specific claim
  2. We will respond within two working days
  3. If the claim is wrong, we will correct or remove it and publish the correction
  4. If we cannot prove a claim to your satisfaction, we will remove it from this page

Questions, challenges, or audit requests

We respond to every legitimate enquiry within two working days.

[email protected]

Hush AI is a drafting and summarisation assistant. It is not a source of medical, legal, or financial advice. Always verify AI-generated outputs before acting on them.

← Back to Hush AI

Convinced? The product will finish the job.

Start free pilot →

Free for two weeks because the product is our only salesman.