Security Policy
Enterprise Security

Security Policy

How Haviqo protects your financial and compliance data.

1. Security Architecture

Protected requests are authenticated and authorised. Important business operations are recorded in the audit trail.

  • Multi-tenant isolation is enforced through tenant-scoped application procedures and PostgreSQL row-level security, with automated negative cross-tenant tests.
  • Server-side role checks distinguish OWNER, CFO, ACCOUNTANT, AUDITOR and HR_MANAGER. Access also depends on tenant membership and the operation requested.
  • Authentication sessions are managed by Supabase Auth under the active project configuration. No fixed public session lifetime is represented here.
  • Protected API endpoints require authentication. Intentionally public endpoints use controls appropriate to their purpose, including request limits.

2. Encryption

  • In transit: HTTPS is used for web and API traffic. Protocol versions and edge controls follow the active hosting-provider configuration.
  • At rest: database and platform storage use provider-managed protections under the applicable provider configuration and terms.
  • Credentials: Supabase Auth manages authentication credentials. Haviqo application code does not store plaintext passwords.
  • Secrets management: API keys, database credentials, and JWT secrets are stored as environment variables in the deployment runtime and are never committed to source code.

3. Access Control

  • Principle of least privilege: users and service accounts are granted only the permissions required for their specific function.
  • RBAC enforcement at both the API layer (tRPC procedures) and the database layer (row-level tenant scoping).
  • Document Templates uses an append-only operational audit trail. Active audit metadata is role-controlled; minimised tenant lifecycle retention events are retained for seven years and are not a permanent copy of document content.
  • Session management: sessions are invalidated on logout and on password change. Concurrent session limits apply.

4. Data Residency

Haviqo does not represent that all customer data is stored in the UAE. The current service-specific hosting locations, subprocessors and transfer position are described below and must be read with the applicable service and data-processing terms.

Core data (database, authentication, file storage) is hosted in Frankfurt, EU. Some sub-processors (Groq, Upstash, Resend) are US-based. Transfers are governed by each provider's contractual terms; formal DPAs are being established in accordance with UAE PDPL.

5. Audit Logging

Document Templates write operations create append-only operational audit metadata. Active audit metadata is visible only to authorised roles. Minimised tenant lifecycle retention events are retained for seven years and do not contain document content or permanent raw identifiers.

Document Templates active audit metadata is available to authorised roles within the tenant. V6.1B does not provide audit export or post-deletion tenant access.

6. Vulnerability Management

  • Dependencies are monitored for known vulnerabilities using automated scanning.
  • Security fixes are prioritised according to severity, exploitability and service impact. No universal public remediation SLA is represented.
  • Independent security testing may be commissioned on a risk basis. This policy does not claim continuous third-party certification.
  • Code changes pass automated tests and controlled release gates, with peer review where the release process requires it.

7. Incident Response

In the event of a security incident or personal data breach, Haviqo follows a defined incident response process:

  • Detection, assessment and containment are prioritised according to the incident's verified scope and severity.
  • Internal escalation to the Data Protection Officer and senior management.
  • Affected customers are notified within applicable legal and contractual periods after the necessary assessment.
  • Regulatory notifications are made where required, to the competent authority and within the applicable period.
  • Material incidents receive a documented post-incident review and remediation follow-up.

8. Employee Security

  • Access to customer data is limited to authorised personnel with a documented operational need.
  • Security responsibilities are communicated to personnel with access to protected systems.
  • Access to production systems is restricted to authorised personnel on a need-to-know basis.
  • Employee access is revoked immediately upon termination.

9. Third-Party Providers

Third-party providers are reviewed on a risk-based basis and governed by their applicable contracts and data-processing terms. See the DPA for the current disclosed subprocessors and transfer position.

10. Responsible Disclosure

If you discover a security vulnerability in the Haviqo platform, please report it responsibly to . We aim to acknowledge and investigate promptly. No fixed response SLA applies unless separately agreed. We do not pursue legal action against researchers who report vulnerabilities in good faith. security@haviqo.com.

Security Contact

To report a vulnerability or security concern: security@haviqo.com

Last updated: 10 July 2026. Version 1.0.