Legal

Security Overview

Last updated: September 18, 2026

HardLabs customers may entrust us with proprietary hardware designs, firmware, source code, schematics, BOMs, technical documentation, and other valuable intellectual property.

Protecting that information is an important part of how HardLabs designs and operates its Services.

Infrastructure

HardLabs currently uses:

Vercel

Application hosting and deployment.

Cloudflare R2

Object storage for technical files and Customer Content.

Clerk

Authentication and account management.

OpenAI and Anthropic

AI inference for applicable AI-assisted workflows.

Google Workspace

Business communications.

Access Control

Internal access to Customer Content and production systems is limited to persons who reasonably require access for:

  • operations;
  • engineering;
  • customer-requested support;
  • security;
  • legal compliance.

Authentication

Customer authentication is handled using Clerk.

HardLabs relies on established authentication mechanisms rather than storing user passwords directly within HardLabs application code.

Encryption

Production web communications use encrypted transport.

HardLabs relies on encryption and security capabilities supplied by its cloud infrastructure providers for data stored within their systems.

Customer Isolation

HardLabs designs its application so that customers cannot access another customer's Customer Content through normal product functionality.

Customer Content

HardLabs treats customer engineering files as confidential information.

Customer Content is not:

  • publicly exposed by default;
  • sold;
  • provided to another customer;
  • used for generalized AI training without express opt-in.

Analytics Isolation

Microsoft Clarity and Google Analytics are intended for public website analytics.

They should not be used to record authenticated HardLabs engineering sessions containing proprietary:

  • schematics;
  • PCB layouts;
  • firmware;
  • BOMs;
  • source code;
  • simulation output.

AI

Relevant portions of Customer Content may be sent to OpenAI or Anthropic when necessary to perform a requested AI operation.

See the HardLabs AI & Customer Data Policy for details.

Security Incidents

HardLabs investigates suspected security events and takes reasonable measures to contain and remediate confirmed incidents.

Where legally or contractually required, affected customers will be notified.

Security Contact

Security issues may be reported to:

adam@hardlabs.io

See also our Vulnerability Disclosure Policy.