Hoicrom

TECHNOLOGY

The engineering
behind HOICROM.

Architecture, security and privacy, explained clearly: this is what stands behind every decision the system makes.

For those who decide and those who review:from the big picture down to the last protocol.

EVERYTHING RUNS ON HOICROM CORE

  • Identity
  • Permissions
  • Policies
  • Risk
  • Decision
  • Human approval
  • Audit

ARCHITECTURE AND STACK

One shared technology base.

HOICROM Core, SECURE and BUILD share the same layers. This is what sits in each one.

  1. Applications and products layerWhere SECURE and BUILD run, over encrypted APIs.
    • TypeScript
    • Python
    • Node.js
    • REST
    • GraphQL
    • TLS 1.3
  2. HOICROM CoreWho you are and what you can do: identity and access.
    • OAuth 2.0
    • OpenID Connect
    • SAML 2.0
    • JWT
  3. Processing servicesThey analyse AI activity in real time.
    • Apache Kafka
    • Webhooks HMAC-SHA256
  4. Data layerEncrypted and isolated per customer.
    • PostgreSQL
    • Redis
  5. Container infrastructureAutomatic scaling and deployment as code.
    • Docker
    • Kubernetes
    • Terraform

HOICROM SECURE

The technology of the three layers.

Prevention, detection and control, on the same Core.

Seatbelt

Prevention
Where it acts
  • WebExtensions
  • Endpoint agent
  • HTTP(S) proxy
What it detects
  • IBAN · ISO 13616
  • Luhn
  • DNI/NIE
  • NER
  • OCR
  • Document classification
How it protects
  • Pseudonymisation
  • FPE · NIST SP 800-38G

Radar

Detection
Collects
  • OpenTelemetry (OTLP)
  • Apache Kafka
  • ClickHouse
Detects
  • Sigma rules
  • scikit-learn
  • PyTorch
Tags
  • MITRE ATLAS
  • OWASP Top 10 for LLM
Alerts your SIEM
  • Syslog (RFC 5424)
  • CEF
  • Signed webhooks

Airbag

Control
Decides
  • Open Policy Agent
  • Rego
  • Allow · Review · Block
Intercepts
  • MCP
  • REST
  • gRPC
Approves
  • WebAuthn / FIDO2
  • Email
  • Webhooks
Connects to your systems
  • REST
  • OAuth 2.0
  • SCIM 2.0
  • SAML 2.0 / OIDC
  • SMTP / IMAP

HOICROM BUILD

The technology of the agents.

How they connect, run and get tested.

  • Tool connection
    • Model Context Protocol
    Each agent plugs into your systems in a standard, auditable way.
  • Orchestration
    • LangGraph
    • LangChain
    The agent's steps, tools and decisions, in a graph.
  • Durable execution
    • Temporal
    A process lasting hours or days is not lost if something fails.
  • Tool calls
    • Function calling
    • JSON Schema
    Every action is validated before it runs.
  • Memory
    • pgvector
    • PostgreSQL
    Context and history of each agent.
  • Isolation
    • Docker
    • Firecracker
    • gVisor
    Each agent runs in its own isolated environment.
  • Per-action permissions
    • OAuth 2.0
    Narrow-scope, short-lived tokens.
  • Testing
    • Evals
    • Regression
    Before every deployment, we check that the agent's behaviour has not changed.

SECURITY AND PRIVACY

Your data, under control.

How we protect the system, and what we do, and don't do, with your data.

Security

  • EncryptionTLS 1.3 + HSTS · AES-256-GCM · Argon2
  • Strong authenticationMFA: TOTP (RFC 6238) · WebAuthn/FIDO2
  • Access controlRBAC with least privilege · ABAC
  • Immutable auditHash-chained log across Secure and Build
  • MonitoringReal-time event correlation (SIEM)
  • Secure codeSAST · SCA · DAST + CI/CD checks on every deployment
  • Regular penetration testing [CONFIRM]
  • Incident response plan [PENDING]

Privacy and data

  • PseudonymisationSensitive data is tokenised before it reaches the AI.
  • Retention and deletionConfigurable: automatic or on request.
  • Data residencyEU by default [CONFIRM].
  • GDPRWith a Data Protection Officer [CONFIRM].
  • ISO/IEC 27001Aligned with the standard; certification [CONFIRM].
  • No training on your dataNever used to train third-party models.

DEPLOYMENT

Choose how you run it.

The same stack in all three models.

  • SaaS · Managed by HOICROMMulti-tenant on Kubernetes. Quick to start.
  • Enterprise · In your cloud or on your serversInstalled in your environment, with the same stack and under your control.
  • Hybrid · Part yours, part managedCombines your environment with services managed by HOICROM.

Want to see how it fits your company?

Talk to an engineer or request a demo.