Security Statement
Version: 2026-10-05.v1. Effective date: 5 October 2026. Operator: ABSOLUTE SERVICES (UEN 53464936W), a sole proprietorship registered in Singapore and owned by LEE KOK WAN. "Hail Pilot" is the name of the product and service operated by ABSOLUTE SERVICES ("Hail Pilot", "we", "us"). Registered address: 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051.
This Statement describes the security measures that operate in the Service on the version date above. The Terms of Service at /legal/terms refer to it, and the Data Processing Agreement at /legal/dpa contains the contractual security obligations we owe you. Capitalised words have the meaning given in the Terms. This Statement lists no control that we do not operate today, and it says plainly what we do not yet have. It is not a certification.
1. Where and how the Service runs
1.1 Production systems are hosted in Singapore, on servers that we rent from a hosting provider and operate ourselves. We administer the operating system, the database and the application; the provider supplies the hardware, power and network.
1.2 The website and the API are served through a content delivery network that provides DNS, TLS termination, a web application firewall and bot protection at the edge.
1.3 Third parties that process Merchant Data, and the country each one operates in, are listed in the Sub-processor List at /legal/subprocessors.
1.4 Hail Pilot is operated by a small team. There is no separate security function. The people who operate the Service are the people who administer it.
2. Encryption
2.1 In transit. Connections between your browser, the browser extension, Platforms and our systems are encrypted using TLS. We instruct browsers to use only encrypted connections to our domains.
2.2 At rest. Buyer personal data fields and the credentials you give us for Connectors are stored in the database as encrypted blobs. The encryption keys are held separately from the database. Each blob records the version of the key that encrypted it, so that keys can be rotated without re-encrypting everything at once.
2.3 Backups. The monthly off-site backup copy described in clause 8 is encrypted on our host before it is uploaded.
2.4 We do not name ciphers, key lengths or protocol versions in this Statement, and we do not warrant any particular algorithm. We answer those questions in the security questionnaire described in clause 14.
3. Sign-in, sessions and requests
3.1 Passwords are stored only as salted hashes produced by a memory-hard hashing function. We never store or log a password in clear text.
3.2 Sessions are held on the server. Your browser receives only a session cookie that is marked HttpOnly, Secure and SameSite, so that scripts cannot read it and it is sent only over encrypted connections. A session ends when you sign out or when it expires.
3.3 Every request that changes data must carry an anti-forgery token that matches a cookie set by us, which prevents another website from making changes through your signed-in browser.
3.4 You may also sign in with a Google account. In that case Google verifies your identity and we receive your name and email address.
4. Tenant isolation
4.1 Each Merchant has its own workspace. Every signed-in request is bound to one workspace, and the application filters every data query by that workspace. A Merchant User sees only the data of the workspaces the Merchant has admitted them to.
4.2 Cross-merchant Network Signals are built from pseudonymised tokens, not from names, emails or phone numbers. Raw Buyer personal data is never shared between workspaces. The Privacy Policy at /legal/privacy describes Network Signals in full.
4.3 Vector embeddings used by AI Features are stored with the Merchant's identifier and, where our vector database is used, in a separate collection per Merchant.
5. Logging
5.1 We keep an audit log of security-relevant actions in your account, including sign-ins and account registration, and we record every automated retention purge, Shopify privacy request and chargeback decision. Audit records are kept for the period stated in the Retention Schedule at /legal/retention.
5.2 We keep a forensic record of every inbound Platform webhook, including whether its signature was verified, so that a disputed event can be reconstructed.
5.3 We use an error-monitoring service to detect faults. Where it records a session replay, text is masked and media is blocked before the replay leaves the browser.
6. Uploaded files
6.1 Files uploaded as evidence are scanned for malware in two ways: a hash of the file is checked against a third-party malware database (the file itself does not leave our systems for this check), and the file is then scanned by a malware scanner that runs on our own host.
6.2 Uploaded files are stored in object storage that is separate from the database, and the database holds only the file's metadata and storage reference.
7. AI Features
7.1 Inputs to the buyer-reply, copilot, dispute-drafting and case-analysis AI Features are passed through automated screening designed to detect prompt-injection attempts before they reach a model.
7.2 Every AI-drafted reply to a Buyer is checked by an automated content-moderation service when it is generated, and a draft that fails that check cannot be sent as drafted. If a Merchant User edits a draft, the edited text is the Merchant User's own message and is not re-checked.
7.3 By default an AI-drafted Buyer reply is sent only after a Merchant User approves it. Auto-Send is off unless you switch it on under the AI Transparency Notice at /legal/ai.
7.4 We do not train models that are shared across Merchants on Merchant Data. The model providers we use are listed in the Sub-processor List.
8. Backups and recovery
8.1 A backup of the production database is taken weekly and copied to an off-site storage provider. A further monthly copy is encrypted on our host and sent to a second storage provider in a different company, so that no single provider holds our only copy.
8.2 Backup copies are kept for the periods stated in the Retention Schedule.
8.3 We keep a written procedure for restoring the Service from backup.
9. Secrets and administrative access
9.1 The tokens and keys you authorise when you connect a Platform are stored encrypted as described in clause 2.2 and are used only to operate the Connector. When you disconnect a Connector, its credentials are removed as the Retention Schedule describes.
9.2 Administrative access to production systems is limited to the persons who operate the Service.
10. Payments and card data
10.1 Subscription payments are collected by a payment provider licensed in Singapore, through its hosted checkout. We never receive, process or store full card numbers, card security codes or magnetic-stripe data. For our own subscription billing we hold no card data at all; our payment provider holds it. In chargeback cases we hold only the card network (brand) and the result codes of address and card-verification checks that your payment processor provides.
10.2 We are not a payment service provider. We do not hold, transfer or settle funds, and we hold no licence under the Payment Services Act 2019, because our activity does not require one.
10.3 When we prepare chargeback evidence for you, we do not receive full card numbers from you, your payment processor or the card networks. The Chargeback Evidence Addendum at /legal/chargebacks describes what we do receive.
11. Regulatory position
11.1 The Service is not designated as critical information infrastructure, and Hail Pilot is not otherwise designated, under the Cybersecurity Act 2018 (Singapore). Our security programme is voluntary and standards-based, not the result of a regulator's direction. We review this position at least once a year.
11.2 Our obligations as an organisation and as a Data Intermediary under the Personal Data Protection Act 2012 (Singapore), and as a Data Processor under the Personal Data Protection Act 2010 (Malaysia), are set out in the Privacy Policy and the Data Processing Agreement. Our Data Protection Officer can be reached at business@hailpilot.com.
12. What we do not have today
12.1 No independent certification. We hold no third-party security or data-protection certification, attestation or audit report under any standard. We do not use any certification mark.
12.2 No external penetration test. Internal security reviews of the Service were carried out in April 2026 and in May 2026. Neither was performed by an independent third party, and we do not describe them as penetration tests.
12.3 No status page. Availability is handled as described in the Service Availability Statement at /legal/availability.
12.4 No cyber insurance bound. We do not currently hold cyber-liability or technology professional-indemnity insurance. The Terms of Service state the limits of our liability, which do not depend on insurance being held.
12.5 No security questionnaire on file. We answer questionnaires on request under clause 14; we have not pre-published one.
13. Roadmap of assurance
13.1 We intend to obtain, in this order: cyber-liability insurance; the CSA Cyber Essentials mark issued under the Cyber Security Agency of Singapore's certification scheme; an external penetration test by a provider licensed in Singapore; and the Data Protection Trustmark administered by the Infocomm Media Development Authority.
13.2 These are intentions, not commitments, and we give no dates. We do not claim any of them until it is achieved, and we update this Statement, with a new version on the legal changelog page, when one is.
14. Security questionnaire and how to reach us
14.1 If you need a completed security questionnaire, or more detail than this Statement gives, email business@hailpilot.com with the subject "Security questionnaire". We acknowledge within 5 business days and tell you when to expect the completed answers. We answer in writing and only to the extent that the answer is true on the date given. We may ask you to sign a confidentiality undertaking before we share internal detail.
14.2 To report a security weakness in the Service, use the Vulnerability Disclosure Policy at /legal/vdp.
14.3 If you suspect that your account has been accessed without authority, tell us at business@hailpilot.com without delay, as the Terms require.
14.4 Security Incidents affecting Merchant Data are notified to you within the times, and in the manner, stated in the Data Processing Agreement.
15. Changes
We may change this Statement. Because the Terms refer to it, we will not reduce the overall level of protection it describes during your subscription term. Every version is listed on the legal changelog page at /legal/changelog.