Hebbia
Multi agent AI platform for finance and legal work whose Matrix runs an agent swarm over thousands of documents, synthesizing cited, auditable answers that would take analyst teams days.
Hebbia builds AI for document-heavy work in finance and law. Its two products share a design principle: the analyst can trace any conclusion back to the page it came from.
Matrix is a grid. Documents form the rows, analytical questions form the columns, and the system resolves each intersection separately against that row's sources. A single instruction can produce a full workup on a company — valuation and growth, leverage and maturity profile, credit ratings, segment reporting, recent acquisitions, shareholder register and activist positions, governance and takeover defenses, leadership changes, strategic risks — each answer carrying the filings, transcripts and presentations it was drawn from, and the whole assembling into a slide deck. The pitch is complete traceability back to every finding, so an analyst audits rather than trusts.
Max is the conversational counterpart, an always-on analyst that researches and analyses a deal and returns client-ready spreadsheets, slides and reports. It can source material itself, draft a presentation, build an Excel model, or run a saved skill.
The platform is sold to investing, banking, legal and corporate finance teams, and the security posture reflects that buyer. Customer data is never used to train Hebbia's models or those of any model provider it works with; each customer's data sits in a siloed environment isolated from every other; and Hebbia states it has no direct access to customer data, with production access restricted through just-in-time management.
Processing runs across the US and EU with regional options for storage and inference, and a dedicated tenant is available. Hebbia holds SOC 2 Type II and ISO/IEC 42001, is GDPR and CCPA aligned, encrypts at rest with AES-256 and in transit with TLS 1.2 or better, and publishes a trust center. Administrators can see who accessed what data, when, and what they did. Pricing is sales-led.
Vendor details
Canonical URL
https://hebbia.com
Category
Enterprise operations agent
Company status
independent
Use cases & customers
In practice
A private credit team needs to pull covenants and loan terms from a portfolio of agreements before a committee meeting. Matrix reads every document in parallel and returns the terms in a cited, auditable grid within minutes.
An investment banker is prepping for a client meeting on a beverage company. They ask Matrix to synthesize key takeaways across two hundred earnings calls and filings, and it drafts a formatted brief with sources attached.
A law firm must review a hundred credit agreements for clauses that deviate from its standard template. Hebbia's agent swarm compares them all at once, flags the outliers, and categorizes each by risk level.
Sources & related URLs
Related / legacy domains
Agentic Index coverage score
5.5 / 14 capabilities · 39%
| Integrations & Tool Calling | Partial |
|---|---|
|
Outside material comes in, but nothing documents a connector catalog or an authenticated write. Max opens with an Auto-source affordance, and the vendor's worked example shows analyses resolved against bundles of customer supplied filings, transcripts and investor presentations, with individual figures attributed in product to third party financial data providers. So the platform reaches beyond its own walls to read material. Nothing documents a write or update in an outside system, such as a ticket or a posted record; the output is spreadsheets, slides and reports delivered back to the analyst. No named integration catalog, custom tool framework or authenticated action framework appears in the navigation, the product pages or the security page. Data provider names appear first party only as attributions inside a synthetic demonstration, which is not an integration catalog. Sourcehebbia.com/product and hebbia.com/matrixread 2026-09-12 |
|
| Workflow Orchestration | Full |
|
Matrix and Max both break work into many steps. Matrix is a grid where a document set forms the rows and analytical questions form the columns. The vendor's worked example runs eighteen distinct analyses per row, among them valuation, leverage, credit ratings, segment reporting, shareholder register, governance, leadership and risks, each resolved separately against the row's sources with its own citations, then assembled into a generated slide artifact. Producing that from one instruction is multi step execution with each branch resolved on its own. Max is the second surface: it "researches and analyzes any deal to produce client-ready spreadsheets, slides, and reports", with Auto-source and saved skill affordances in its published interface. The evidence is a vendor published demonstration using synthetic companies rather than architectural documentation. It is first party about the product's own output structure, though no BPMN, named runtime or agent count is published. Sourcehebbia.com/matrix and hebbia.com/productread 2026-09-12 |
|
| Knowledge Grounding & RAG | Partial |
|
Matrix reasons over a document set assembled for each task, and nothing persists as a maintained retrieval structure between tasks. It promises to "reason over any volume of documents or companies with precise analysis and complete traceability back to every finding", and the vendor's worked example scopes each row to a named bundle of source documents: 10-Qs, DEF 14As and earnings call transcripts. That is a corpus gathered for the analysis, however large the volume. No page describes an index, graph or embeddings layer over the firm's corpus that persists and stays queryable between matrices, and forum.hebbia.com is a community surface rather than documentation. Sourcehebbia.com/matrix and hebbia.com/productread 2026-09-12 |
|
| Human Oversight & Guardrails | Partial |
|
Oversight means checking output, not a configurable gate over action. Matrix is built so every finding is checkable, with "complete traceability back to every finding": each cell carries the source documents it was drawn from, and the vendor's worked example shows attribution for each claim down to filing and date. An analyst is expected to audit before relying, so a person validates each output. There is no approval queue or reviewer role, and no policy layer or administrator setting decides which outputs require sign off; the oversight comes from how results are presented, not from a gate the vendor ships. Matrix and Max produce analysis and documents rather than taking authenticated action in outside systems, so there is little to gate. Sourcehebbia.com/matrix and hebbia.com/productread 2026-09-12 |
|
| Security, Identity & Governance | Partial |
|
The attestations are strong and first party, but no access controls for the customer are documented. Hebbia displays SOC 2 Type II and ISO/IEC 42001:2023 as held, along with CCPA and GDPR, encrypts with AES 256 at rest and TLS 1.2+ in transit, and runs a trust center at trust.hebbia.ai. The nearest thing to an access control is Zero-Trust Access Control, where "Hebbia doesn't have direct access to your data. Production access is restricted through just-in-time access management." That governs Hebbia's own staff access to its production estate, not who inside the buyer's organization can do what. No SSO, SAML, SCIM, OIDC or RBAC appears, and no roles or granular permissions. Access controls may still appear in the controls list on the trust center, which does not show its contents as plain text. Sourcehebbia.com/securityread 2026-09-12 |
|
| Observability & Auditability | Partial |
|
There is a data access audit, but no record of what the agent did. Under "Full control", the security page offers to "see exactly who accessed your data, when they accessed it, and what they did, with complete insight into your operations." Who, when and what make it an audit trail rather than a usage report, but its object is data access by people, not agent execution. No run trace or tool call record is documented, and nothing covers retention, export or SIEM integration; complete insight into your operations carries no checkable commitment. Matrix's complete traceability back to every finding is citation provenance shown to the analyst inside a result, not an administrator's audit of agent behavior. Sourcehebbia.com/securityread 2026-09-12 |
|
| Memory & State Persistence | Not documented |
|
No memory layer is described: no memory scope per user or tenant, no lifetime or purge path, and no way to read or write it. Nothing describes conversation state carried across turns, let alone across sessions. The features nearby are something else. Document sets attached to a matrix are the task corpus, and citation traceability is answer provenance. The data access audit logs people, and siloed environments for each customer are about isolation. None is a store the agent writes from its own runs and later reads back. Sourcehebbia.com/product, hebbia.com/matrix and hebbia.com/securityread 2026-09-12 |
|
| Deployment & Data Residency | Full |
|
Region and tenancy are both named in one sentence on the security page: "Hebbia runs across the US and EU, with regional processing available for storage and inference, and can deploy on a dedicated tenant if needed." Regional processing that covers inference as well as storage is a real mechanism rather than legal cover, and a buyer with a different requirement gets a different answer. Isolation is stated independently: "Your data is stored in siloed environments, fully isolated from every other customer." No first party page supports on premises deployment, which is a different thing from a dedicated tenant. Sourcehebbia.com/securityread 2026-09-12 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Two whole products are sold for a buyer to choose between: Max, an always on analyst producing spreadsheets, slides and reports, and Matrix, a grid analysis over document sets. Each does its own job, so removing one leaves the other complete. Max's published interface also carries a "Use a skill" action beside "Draft a presentation", "Research a topic" and "Build an Excel model", which implies saved reusable units, and four solution pages exist, for Investing, Banking, Legal and Corporate. Two products make a thin pack, and the skills action is unexplained: there is no library or listing a customer browses and adopts, and no page says what a skill contains or where skills come from. The solution pages are market segmentation rather than packaged assets. Sourcehebbia.com/productread 2026-09-12 |
|
| Triggers & Channel Coverage | Not documented |
|
Every documented route in is a person typing. Max is invoked from a chat box that greets the user with "I'm Max. How can I help?" and invites them to ask anything, and Matrix from a grid the analyst builds by adding rows and columns. No event, schedule or webhook starts work, and there is no inbound queue or monitoring trigger. No channel exists beyond the web application: no email address for the agent, no Slack or Teams presence, and no mobile app or extension. Sign in runs through search.hebbia.ai, a single web front door. Max's Auto-source affordance sources material once a task is running; that is the agent reaching out mid run, not an event starting one. A scheduled matrix refresh or a filing alert would suit this product, but neither is offered. Sourcehebbia.com/product and hebbia.com/matrixread 2026-09-12 |
|
| Model Flexibility & Routing | Partial |
|
Hebbia works with more than one outside model provider but gives the customer no choice. The security page states that documents, prompts and outputs are never used to train "Hebbia's models or any model provider we work with", and the plural shows routing across providers on the vendor's side. No page gives the customer or an administrator a model picker, model policy or default override, or even lists the providers in use. No provider is named first party. Sourcehebbia.com/securityread 2026-09-12 |
|
| APIs, SDKs & MCP Extensibility | Not documented |
|
Hebbia publishes no interface for calling its platform: no REST or GraphQL API or SDK, no developer portal, open or gated, and no MCP server or A2A agent card. Neither the primary navigation nor the footer, which run from Product and Solutions to Policies and Contact, has a Developers entry, and no docs or developer subdomain is linked. forum.hebbia.com is a community host, not developer documentation. The site documents little in text, so this silence is weaker evidence than it would be for a better documented vendor. Sourcehebbia.com/product and hebbia.com/security navigation and footerread 2026-09-12 |
|
| Testing, Debugging & Optimization | Not documented |
|
A buyer has no published way to evaluate a change: no evaluation harness or scored test cases, no quality gate in a release path or controlled experiment after deployment, and no accuracy reporting a buyer could use. A vendor's published benchmark of its own product would be marketing rather than a test surface. Complete traceability lets an analyst check a finding by hand, which verifies one output rather than testing a change before it ships. Sourcehebbia.com/product, hebbia.com/matrix and hebbia.com/securityread 2026-09-12 |
|
| Browser & Computer Use | Not documented |
|
No browser or computer use is documented: no hosted or local browser, desktop session, or remote or local computer control appears. Matrix and Max work on documents supplied to them and return spreadsheets, slides and reports, so questions about breaking when UI elements change, or whether control runs native, sandboxed or in a VM, do not arise. Max's Auto-source affordance gathers material at run time, but nothing published describes how, and data provider APIs are the likelier shape for a finance product drawing on third party financial data. Sourcehebbia.com/product and hebbia.com/matrixread 2026-09-12 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Hebbia released its September 2026 updates, introducing the Hebbia MCP which allows users to access Matrix and Project Intelligence directly within Claude, ChatGPT, Cursor, and internal applications. The update also enables the Max agent to generate audio briefs and interactive dashboards, and adds organizational sharing and permission controls for custom Skills.
Bears on: MCP / tool calling / API
View sourcePricing
Contact for pricing
Related vendors
- 11th Estate — Agentic platform whose AI engine scans markets, matches an…
- Adopt AI — AI CPA firm whose agents run reconciliations, close, AP and AR, and…
- Aera Technology — Decision intelligence platform where an always on agent executes…
- Akro AI — On premise operational intelligence that automates document heavy…
- alfred_ — AI executive assistant that triages the inbox overnight and scores…
- Alloy.ai — Commerce intelligence system for consumer brands that unifies four…
Alternatives to Hebbia
The closest documented capability profiles to Hebbia among enterprise operations agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- ChipAgents4.5 / 14Adds documented APIs, SDKs & MCP Extensibility
- Porters5.5 / 14Adds documented Triggers & Channel Coverage
- Sindri7.5 / 14Adds documented Triggers & Channel Coverage
- Thefword6.5 / 14Adds documented Triggers & Channel Coverage and APIs, SDKs & MCP Extensibility
- Friendly5.0 / 14Adds documented Triggers & Channel Coverage
- Kenmei7.0 / 14Adds documented Triggers & Channel Coverage
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded