How Haviqo protects your financial and compliance data.
Protected requests are authenticated and authorised. Important business operations are recorded in the audit trail.
Haviqo does not represent that all customer data is stored in the UAE. The current service-specific hosting locations, subprocessors and transfer position are described below and must be read with the applicable service and data-processing terms.
Core data (database, authentication, file storage) is hosted in Frankfurt, EU. Some sub-processors (Groq, Upstash, Resend) are US-based. Transfers are governed by each provider's contractual terms; formal DPAs are being established in accordance with UAE PDPL.
Document Templates write operations create append-only operational audit metadata. Active audit metadata is visible only to authorised roles. Minimised tenant lifecycle retention events are retained for seven years and do not contain document content or permanent raw identifiers.
Document Templates active audit metadata is available to authorised roles within the tenant. V6.1B does not provide audit export or post-deletion tenant access.
In the event of a security incident or personal data breach, Haviqo follows a defined incident response process:
Third-party providers are reviewed on a risk-based basis and governed by their applicable contracts and data-processing terms. See the DPA for the current disclosed subprocessors and transfer position.
If you discover a security vulnerability in the Haviqo platform, please report it responsibly to . We aim to acknowledge and investigate promptly. No fixed response SLA applies unless separately agreed. We do not pursue legal action against researchers who report vulnerabilities in good faith. security@haviqo.com.
Security Contact
To report a vulnerability or security concern: security@haviqo.com
Last updated: 10 July 2026. Version 1.0.