Authenticated access
Customer activity is tied to authenticated identity and organization membership. Authentication establishes who is acting; it does not grant infrastructure-testing authority.
Trust & Safety
Hagon is designed so customers can understand what was discovered, what they authorized, what Hagon did, what evidence supports a conclusion, and where the product deliberately stops.
Customer activity is tied to authenticated identity and organization membership. Authentication establishes who is acting; it does not grant infrastructure-testing authority.
Customer data and operational records are separated by organization and protected by enforced access boundaries.
Hagon can show what is publicly visible before receiving permission to directly assess customer infrastructure.
Discovery, control verification, asset review, and active-assessment authority are separate. Customers explicitly choose the networks and verified services Hagon may assess.
Observations, technology matches, vulnerability candidates, validation evidence, findings, and score remain distinct. A match is not automatically a finding.
Standard operation uses least-intrusive, non-destructive checks with centrally enforced safety limits. It does not include denial-of-service testing, brute force, persistence, destructive exploitation, or lateral movement.
Hagon collects the evidence needed to establish and explain security conditions while minimizing unnecessary raw artifacts and sensitive content.
Authorization, evidence, findings, ownership, remediation, revalidation, and score changes are designed to remain explainable over time.
Deployment, backup, recovery, and verification procedures are tested rather than assumed. Hagon does not publish unsupported uptime, compliance, or breach-prevention claims.
During private beta, security reports can be sent to support@hagontech.com. A dedicated public security-reporting channel may be introduced before broader availability.
Private beta
Hagon is still in private beta. Formal compliance claims, SLAs, and final security documentation are not yet published.