Security & Compliance

Revolutionary AI, built on security fundamentals

Learn how Hazel protects and respects your data, with safety and privacy practices designed to meet the rigors of the financial advisory industry.

Your data is yours. Full stop.

Hazel implements strict policies and procedures to ensure your data always stays yours.

Zero data retention with AI model providers

Your data is processed strictly to deliver the response you requested, then immediately deleted. It is never stored, logged, or reused beyond what is needed to fulfill your request.

No third-party models are trained with your data

The AI model providers and subprocessors we partner with are contractually prohibited from using customer data for training, model improvement, or any secondary purpose.

Take full control of data within Hazel

Choose what Hazel records, how long it’s retained, and when it’s deleted across video, audio, transcripts, and meeting summaries to align with your firm’s security and compliance requirements.

Compliance and security standards you can stand behind

PRIVACY

Results you can trust, data you can verify

Every piece of data referenced in the plans built by Hazel includes a verifiable source, confidence score, methodology, and list of assumptions that Hazel used to create it.

Your frequently asked security questions, answered

hidden on live site

FAQ items are created from the CMS.

No. None of the vendors we partner with trains on user data. Furthermore, we have zero data retention (ZDR) with key AI model providers, meaning AI subprocessors delete data immediately after first use, storing it only for the minimum time required to complete processing and never using it for model training. AI providers (e.g., OpenAI, Anthropic) and all of Hazel's third-party processors do not store user data. Because meeting audio and video files are voluminous and require resilient, fault-tolerant handling, our transcription partners may briefly store them solely to ensure reliable processing, after which they are promptly deleted.

We encrypt all data in transit (TLS 1.2+) and at rest (AES256). All data is stored in the United States. Altruist has an in-house security team that is working to make sure all data held by Hazel is safe and secure. Hazel has achieved SOC 2 Type I and completed an independent penetration test in November 2025, validating the design of our controls and the resilience of our platform. Altruist maintains a comprehensive cyber insurance program designed to protect the integrity of our systems and client data.

You control data retention through Hazel's settings. You can choose to retain or delete audio, video, and transcripts using role-based access controls (RBAC). You can also control data retention at the meeting level for specific meetings. Hazel can only access households and data that you have permission to view within your firm. If you request that your data be deleted, we'll remove it, though Hazel will stop functioning without access to your data. If you want to delete your data, contact us here.

Yes. Altruist maintains a comprehensive cyber insurance program, including $15M in total aggregate coverage to support breach response and resilience (e.g., business interruption, data recovery, extortion, and liability). Altruist also maintains documented Business Continuity and Disaster Recovery plans, reviewed at least annually. A public-facing Business Continuity Plan is available for download at altruist.com/legal.

Yes. Contact us and we'll provide our complete security and privacy policy documentation to qualified parties.

Your data is safe with us