01Our approach
HUMXN exists to prove where training data came from, so the integrity of our records matters as much as the confidentiality of the data. We design for least privilege, verifiable records and defense in depth, and we describe here only measures that are in place today.
We do not currently hold third-party security certifications. We'll share our security documentation under NDA on request; contact security@humxn.io.
02Encryption in transit
All traffic to the website, registry and marketplace is served over HTTPS using TLS.
03Signed provenance and tamper-evident audit trail
Every registered work has a provenance record signed with Ed25519. Each change to a work is written to a hash-chained, signed audit trail, so altering or removing an earlier entry breaks the chain and is detectable.
The SHA-256 hash of each original is anchored in the Bitcoin blockchain through OpenTimestamps, so the time a file existed can be verified independently, without relying on us. Every order comes with a signed receipt listing each delivered item by ID and hash.
04Account security
Member accounts are protected by:
- Two-factor authentication using time-based one-time passwords (TOTP) from an authenticator app.
- Passwords hashed with scrypt, a memory-hard key-derivation function; we never store passwords in plain text.
05Access control and least privilege
Access to workspaces is role-based: members see and act only on the projects, datasets and briefs their role allows. Internally, access to production systems and data is limited to the people who need it for their work.
Experts working on a brief see only the material required for that task, and the identities of experts are not disclosed to buyers unless the expert has agreed.
06Application and network protections
- Rate limiting on sign-in, forms and APIs to slow down brute-force attempts and abuse.
- SSRF-hardened fetching: when the platform retrieves a remote URL, requests to private, loopback and internal network addresses are blocked.
- Analytics scripts are never loaded on private pages such as the members' dashboard.
07Content safety and personal data protection
Uploads are screened against hash block-lists and a safety classifier before they can enter a dataset. Material that may be child sexual abuse material is blocked and handled under our zero-tolerance process.
Documents and tables are scanned for personal data, which is masked before delivery to buyers. Works showing identifiable people are only offered for training when consent is on file.
08Forensic delivery marks
Licensed deliveries carry a forensic mark that identifies the delivery, which helps trace leaked or redistributed data back to its source and supports enforcement of licence terms.
09Backups and resilience
We take regular backups of databases and stored files and verify them, so that we know they can be restored. Backups are protected with the same access restrictions as production data.
10Vendors
We keep the number of third parties that handle data small, bind them by written agreements, and publish them on our Sub-processors page.
11Incident response
If we become aware of a security incident affecting personal data, we investigate, contain and remediate it, and notify affected customers without undue delay as set out in our Data Processing Addendum and as required by law.
12Responsible disclosure
If you believe you have found a security vulnerability, please report it to security@humxn.io with enough detail for us to reproduce it. We will acknowledge your report, keep you informed, and credit you if you wish once the issue is resolved.
Please act in good faith: do not access, modify or delete data that is not yours, do not degrade the service, do not use social engineering or physical attacks, and give us reasonable time to fix the issue before disclosing it publicly. We will not pursue legal action against researchers who follow these guidelines.

