Hex Security is now ParameterWe're at Black Hat USA 2026

Parameter

[ security ]

Secure by default.Proven by data.

Parameter is built by people who break into companies for a living. We hold our own security to the standard we test everyone else against.

Built by the team that secured:

Apple
Google
Microsoft
U.S. Department of Defense
T-Mobile
Henkel
Epic Games
AT&T
Yahoo

SOC 2 Type II

Parameter is pursuing SOC 2 Type II certification, with controls in place and tested over time.

request status

HIPAA

Safeguards for protected health information, for teams that need them.

request baa

Data residency

Your data is processed in the US and never leaves your assigned infrastructure.

Penetration tested

Parameter is tested by Parameter, continuously, alongside independent third-party review.

[ how it works ]

What we access

When you connect, Parameter gets a scoped, read-only connection. Least privilege, nothing beyond what the test needs.

view required permissions

What happens to your data

Your code is analyzed in isolated environments and destroyed after. Never stored, never used for training. Encrypted in transit and at rest.

read our data policy

How the agents behave

Agents confirm a finding and hold. No escalation without opt-in, scoped to authorized targets, and never blind testing against production.

see the agent safety model

What reaches you

Only validated findings. Nothing surfaces unless it’s been exploited and proven, under 1% false positives.

how we validate findings

Who’s behind it

Least-privilege access, SSO and MFA, background-checked staff, and we run Parameter against Parameter.

see about page

Reach the team.

Questions about security, or a vulnerability to report? Book a call or email security@parameter.ai.

Book a call