Security approach
Hāvin uses authenticated access, database authorization rules, private file storage, time-limited document links, server-side secrets, role-based collaboration, environment separation, monitoring, backups, and administrative controls appropriate to the service’s stage and risk.
Security measures evolve as Hāvin grows. Hāvin does not claim that any system is immune from failure or attack and will communicate material incidents as required by applicable law.
Hāvin Access boundaries
Access is designed around explicit scope, role, information categories, and capabilities. A person who can operate or troubleshoot an asset does not automatically receive private financial, ownership, maintenance, or document records. Expiring and revocable grants are intended to remain enforceable below the user interface.
AI authorization
Ask Hāvin is designed to follow the same authorization boundaries as the underlying ownership record. AI should not retrieve information a user could not otherwise access in the authorized context.
Customer controls
Users should use a unique password, enable available multifactor authentication, keep recovery information current, review collaborators, revoke unneeded access, and promptly report suspicious activity.