Trust

Customer control is part of the product.

Hood is designed around clear identity, controlled permissions, accountable operations, and durable evidence.

Identity
Know which person, agent, system, or organization is acting.
Permissions
Keep consequential actions inside organization-defined authority and approval controls.
Evidence
Preserve important decision and outcome records for review and operations.
Customer control
Enterprise security, deployment, and data requirements are handled directly with the customer.

Trust boundaries

Hood does not treat an AI provider, sandbox, model response, login session, or local credential as a complete authority boundary. Controls should remain independent of the environment being governed and should fail closed when required identity, authority, policy, or evidence services are unavailable.

Public assurance status

Public references to NIST, CISA, MITRE, OWASP, or other standards bodies describe relevant context; they do not mean those organizations certify, approve, or endorse Hood Intelligence. Product availability, assessed controls, hosting region, data retention, and contractual commitments must be confirmed for the customer's specific deployment.

Confidentiality

Hood publishes enough information to explain the control objective and evidence model. It does not publish customer data, credentials, private security findings, proprietary enforcement logic, or other confidential implementation material for search engines or AI systems.