Security
How Headlight protects your firm's data
Built for advisory firms, family offices, trust companies, and wealth management firms that handle sensitive client information.
Your firm is isolated from other customers
Each customer organization is logically isolated. PostgreSQL row-level security enforces tenant boundaries at the database layer. The application applies tenant-scoped access controls on every query.
Encryption in transit and at rest
Customer data is encrypted in transit with TLS and encrypted at rest.
Extra encryption for the most sensitive fields
Contact details, extracted document text, and sensitive financial fields receive additional application-layer field encryption (AES-256-GCM) with centrally managed keys.
You control who can access what
Access uses role-based permissions within your organization. MFA and SSO are available.
Sensitive actions are logged
Audit logging covers sensitive actions, such as revealing protected fields like SSN or EIN.
We do not use your data to train AI
Headlight does not use customer content to train or fine-tune AI models. Inference runs on your documents to classify and extract data, summarize records, and answer questions from your firm's files.
SOC 2 Type II in progress
Headlight is undergoing SOC 2 Type II attestation. We run a SOC 2-aligned control environment. The report will be published in our Trust Center when it is ready.
How we protect your data
Access and sign-in
Authentication is handled by a dedicated identity provider. Multi-factor authentication and SSO are available.
Role-based permissions are scoped to your organization so each user sees only what their role allows.
Data isolation
Headlight is a cloud-hosted, multi-tenant platform where each customer organization is logically isolated.
PostgreSQL row-level security and tenant-scoped application queries ensure one firm's users cannot read another firm's records.
Encryption
Customer data is encrypted in transit with TLS and encrypted at rest for database and document storage.
The most sensitive values get additional field encryption (AES-256-GCM): contact details, extracted document text, and financial fields. Keys are managed centrally.
Audit logging
Security-relevant actions are recorded, including when authorized users reveal protected fields.
Audit events are retained per our security program.
Availability and AI
Headlight is hosted in United States data centers with automated database backups and point-in-time recovery.
AI features run inference only. Customer content is not used to train models. Extracted information goes to your authorized users for review before it is committed to client records.
Questions about security? Email us or read our policies.
security@withheadlight.comTrust Center
This page is an overview for prospective customers. It is not a certification, audit report, or legal opinion. Policies and subprocessors are in our Trust Center.