Security

How Hotam protects your clients' data

You are trusting Hotam with access to your clients' environments. Here is exactly what that access is, how it is protected, and what is not in place yet.

Hotam only reads

  • Every connection asks for read-only permissions and never changes anything in your PSA, RMM, Microsoft 365 or documentation tool.
  • You create the credentials in your own systems, with the narrowest access each offers: an Autotask API user we recommend limiting to organizations and projects, a NinjaOne app with the read-only Monitoring scope, Microsoft Graph read permissions approved by an admin in each client tenant, and an IT Glue key with password access off.
  • You can remove access at any time, for example by deleting the Hotam app in a client's Microsoft tenant or revoking the key in IT Glue.
  • Hotam reads what a check needs: projects and their scope, users, licenses and MFA registration, domains, devices and agent status, and the names of documentation records. It does not read email, files, chats or the content of documents, and never reads passwords.

Your credentials stay sealed

Connection credentials are encrypted with AES-256-GCM before they are stored, with a key that exists only on our server. Each one is bound to your organization and to that one connection, so it cannot be moved to another. Credentials are write-only on screen: once saved, nobody can view them again, including us. They are never logged and never sent to the browser.

Your data stays separate

Every record belongs to one organization. The application filters every query by your organization, taken from your signed-in session, never from the browser. The database enforces the same separation on its own with row level security, so even a faulty query cannot return another organization's data. Automated tests check both layers.

Sign-in and roles

Every person signs in with a password plus a 6-digit code from an authenticator app. This two-step sign-in is required for everyone. Passwords are kept only as salted hashes by our sign-in provider (Supabase Auth), never by Hotam's application in readable form.

Each person has a role in your account: owner, admin, technician or viewer. The server checks the role before every action; screens only hide what a role cannot do.

Who at Hotam can see your data

  • During an onboarding you agreed to: the Hotam person assigned to it, with a banner on screen and every change recorded under their name. Access ends when the onboarding is complete.
  • Otherwise only in a support visit: read-only, with a stated reason, ending after at most 4 hours, and listed in your audit log for your owners and admins to see.

Results you can defend

A result comes from a fixed rule comparing what should be true with what your systems report, with the evidence attached: where it came from, when, and about which user or device. When a system cannot be read, the result is Unknown with the reason. Hotam never shows Passed without evidence.

AI is used only to suggest requirements from a project's scope text, when a person asks for it. Its answer is checked against a strict format before anyone sees it, nothing is saved until a person accepts it, and it never decides a result.

Built against common attacks

  • Database queries never mix in typed text, so input cannot change a query.
  • Everything people type is shown as text, and a strict content security policy runs only our own scripts.
  • Scope text sent to the AI is treated as data, never as instructions, and its answer is validated before it is used.
  • Our server only calls vendor addresses it has checked, and refuses internal and private network addresses.
  • Secrets live only in the server environment; a check of the browser code confirms none reach it.

Where your data goes

These are the only outside services that receive data, and what each one receives:

  • Your own systems (Autotask, NinjaOne, Microsoft 365, IT Glue): Read requests signed with the credentials you created, on connection tests, syncs and QA runs. Nothing is written to them.
  • Anthropic (Claude), the AI provider: Only the project scope text, and only when a person in your account asks for a scope analysis.
  • Supabase: The database that stores your account, and sign-in.
  • Resend: Sends sign-in emails and messages from our website forms: the recipient's email address and the message.
  • Vercel: Hosts the application; your data passes through it on each request.
  • Sentry, when error monitoring is on: Error messages, stack traces and the page path. Cookies, headers, request bodies, query strings and the person are removed before anything is sent.

Data is encrypted in transit between you, Hotam and these services.

What is not in place yet

We would rather tell you than have you find out:

  • Hotam does not hold SOC 2 or any other security certification yet.
  • Hotam has not had a third-party penetration test yet.
  • Automatic backups are not in place on our current database plan. This page will say so when they are.

Questions

For security questions, or our answers to your security questionnaire, write to hello@hotam.io. If you believe you have found a vulnerability, please tell us there first.