Is this your company?Buyers are checking Hdata here. Claim hdata.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.
HData is a software company that makes life easier for energy companies and their regulators. We do this by automating critical comparative analytics for instant insight and improved decision-making. We also automate Federal filings, built the first energy regulatory app marketplace, and pioneered Regulatory AI.
SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Hdata SOC 2 compliant?
Hdata is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Hdata SOC 2 Type I or Type II?
Hdata is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Hdata's SOC 2 for a vendor risk assessment?
Yes. Hdata's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Hdata penetration tested?
Hdata hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Hdata secure?
Security isn't a single yes/no, but Hdata is SOC 2 Type II compliant and holds SOC 2 Type II, SOC 2 Type I. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Hdata have a bug bounty or vulnerability disclosure program?
Hdata hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@hdata.com or via a /security page (Hdata lists a security contact).
Who are Hdata's subprocessors?
Hdata lists 11 subprocessors on its trust center, including Amazon Web Services, Okta, Google Cloud Platform, Elastic Cloud, Datadog. Buyers use this for fourth-party risk review.
Where does Hdata host or store data?
Hdata hosts on AWS, GCP, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information, Personal health information. Data residency details are on its trust center.
Where is Hdata's trust center or security page?
Hdata's trust center is at https://trust.hdata.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
Will HData use my content (AI inputs and outputs, uploaded documents, etc.) to improve/train/fine-tune models or services?
No. Customer Content—including documents uploaded to the Library’s private catalog, AI prompts/inputs, and AI outputs generated from your use of the service—is not used to train, fine-tune, or improve HData’s models or services and is not shared with other customers. We may use de-identified and aggregated service telemetry (e.g., feature usage metrics, performance and reliability data) to operate, secure, and improve the service. This telemetry is not used to reconstruct customer documents or prompts.
Can I request that my data be deleted?
Yes. Current customers: Authorized users can delete any document they uploaded to the Library’s private catalog by selecting the document and clicking Delete. Deleted content is removed from active systems, and backups are overwritten on a rolling schedule. Prior customers: We delete or de-identify Customer Content within 30 days of termination, except where we are required or permitted to retain certain information by law or contract (e.g., security, audit, or legal holds). Any retained data remains access-restricted and protected, and is deleted when the retention obligation ends. Individuals: You may request deletion of your personal data by emailing support@hdata.com. We will process verified requests subject to applicable legal exceptions.
What compliance reports/certifications do you have, and how can I request access to them?
HData maintains a SOC 2 Type II report (covering the applicable Trust Services Criteria). Customers and qualified prospects can request our most recent report by emailing support@hdata.com. We typically provide the report under NDA (or equivalent confidentiality terms) after verifying the requester’s relationship to the customer/prospect.
Do you support Single Sign-On (SSO)?
Yes. HData supports SAML 2.0–based SSO for current customers. To get started, email support@hdata.com to open a ticket and include your identity provider (IdP) details (e.g., Okta, Azure AD, Google Workspace), your preferred SSO domain, and an admin contact for coordination.
Where can I report adverse impacts of one or more of your AI features?
You can report adverse impacts or concerns related to one or more of our AI features by contacting us at ai-impact@hdata.com. Please include as much relevant detail as possible, such as the feature involved, what occurred, when it happened, and any supporting screenshots or documentation, so our team can review and respond appropriately.