Security & Trust
You stay in control
Hirelli puts AI workers to work on real operations, but never at the cost of your control or your data. Here is exactly how that works today, in plain terms.
1. Every sensitive action is approved by you
Agents draft and prepare work; anything that spends money, sends a message on your behalf, changes a campaign, or touches a customer is brought to you for approval first. You see what the agent wants to do and why, and you decide. Read-only analysis runs on its own; actions with real-world effects wait for your yes.
Every decision, and the reasoning behind it, is logged, so you always have an audit trail of what happened and who allowed it.
2. Your data is isolated, and it stays yours
Each organisation's data and agent memory (brand voice, documents, leads, customer messages) is tenant-isolated and never visible to another organisation. We do not sell your data or share it for third-party commercial purposes.
For your account and billing details we act as the data controller; for the business content and contacts your agents work on, you are the controller and we act as your processor, handling that data only on your instructions. Full detail is in our Privacy Policy.
3. Honest AI, by design
Our agents are built to be honest, not just persuasive. Outputs pass through a claim-audit and confidence checks, banned-phrase and anti-hallucination validators reject invented statistics and overblown claims, and sensitive legal or compliance wording is routed to a human instead of being guessed.
When Nova, our voice agent, makes or takes a call, it discloses that it is an AI at the start of the conversation. We would rather earn trust than fake it.
4. Data protection & privacy
We align our data handling with Türkiye's KVKK (Law No. 6698), the EU GDPR, and the UK GDPR, and honour UAE PDPL for users there. Data is encrypted in transit, personal data is deleted within 30 days of account closure (except where the law requires us to keep financial records), and every sub-processor we rely on is listed openly in our Privacy Policy and KVKK notice.
5. Payments
Payments are processed by iyzico. We never see or store your full card number; iyzico handles card data as a separate, PCI-compliant processor.
6. What we are honest about
We are a young company, and we will not pretend to be something we are not. We do not yet hold SOC 2 or ISO 27001 certification, and we will never display a badge we have not earned. What we do have today is what is on this page: approval gates, tenant isolation, honest-AI validators, encryption in transit, and clear data-protection practices. As we grow, we will add formal certifications and say so here when we do.
Security questions or a due-diligence request? Email [email protected] or use our contact form.