Skip to content
Skip to main content

Security and privacy

Security and privacy

Hollow protects your data by default: encrypted in transit and at rest, strictly isolated to your account, and never used to train third-party models unless you explicitly opt in.

Every endpoint runs over TLS, and stored workspace data carries strong encryption at rest. Signing in takes an email and password backed by challenge verification and app-integrity checks, and you can review or revoke any active session from Account settings.

Access control is enforced server-side and scoped to membership: nothing private is reachable through an unauthenticated link.

Two layers of sandboxing keep untrusted content contained. Email HTML renders inside sandboxed iframes, and HollowScript Code steps in Cascade are capability-isolated: a step can only reach the capabilities its uses declaration lists, checked before any code runs.

The data is yours. Export your notes, files and conversation history whenever you like, and deleting your account permanently removes everything tied to it.