Trust

Security & Compliance at Hven

Your business data and AI-visibility results, encrypted at rest and in transit. Built to satisfy your security review on the first pass.

AES-256 at rest TLS in transit

GDPR compliance

We process the business information you give us and the public AI answers we collect about your brand — nothing more.

  • Data subject rights: access, rectification, erasure, portability, and objection — all responded to within 30 days.
  • Privacy requests: contact us at the address on this page — we're finalising our dedicated privacy contact.
  • Supervisory authority: UK ICO (Information Commissioner's Office) is our lead authority for the UK.
We do not sell, rent, or share your data with third parties for advertising. Hven does not track visitors on your website — nothing installs on your site, and we hold no data about the people who visit it.

Data protection

Defence in depth at every layer — transport, storage, and access.

🔒Encryption in transit

All traffic between your browser, the dashboard, and our backend is encrypted in transit with TLS (HTTPS everywhere).

💾Encryption at rest

All databases use AES-256 encryption at rest. Per-tenant data is logically isolated — every read and write is scoped to the owning tenant at the data-access layer.

🗂️Backups

Encrypted backups are managed through our database provider. We're confirming retention specifics and will publish them here.

🌐Network isolation

Our application and database are not exposed directly to the public internet beyond the product's own endpoints; administrative access is restricted to the founding team and protected by strong authentication.

Data location

Your account data is stored with the providers listed below. To run your weekly checks, the questions we ask — which include your business name and market — are sent to the AI providers in the sub-processor table, some of which operate outside the UK/EU, including in the United States and China. We list every one of them plainly below, and we're finalising the full transfer-safeguard details for each as part of updating this page.

  • Hosting: our application runs on Railway. We're confirming and will publish the specific hosting region here.
Questions about where your data lives? Contact info@hven.io.

Access controls

Who can do what, and how we prove it after the fact.

🔑2FA on every account

TOTP-based two-factor authentication available on every account.

👫JWT authentication

Sessions are signed JSON Web Tokens with short-lived access tokens — they expire after minutes, not days.

👥Role-based permissions

Role-based permissions with feature-level gating. Platform-admin capabilities are gated by a dedicated platform-admin role that ordinary tenant accounts do not carry.

🗒️Audit logs

Sensitive account and team actions — role changes, password and 2FA changes, invites, API key issuance — are written to an append-only audit log.

What Hven processes

Hven checks how AI assistants talk about your business. There is no tracking script, no plugin, and no code on your website.

  • Business information you provide. Your brand name, website and profile details — used to run your weekly checks.
  • Public AI answers. The responses AI assistants give to the questions your customers ask, collected from the outside — the same way your customers see them.
  • Your account data. Sign-in details and preferences for the people on your team.
  • Nothing about your website's visitors. Hven does not run on your website, so it collects no data about the people who visit it.
  • No cross-tenant mixing. Each tenant's data is its own walled garden — we never join one customer's data with another's.

Certifications & roadmap

What we have, and what we're working towards.

🔵Cyber Essentials (UK)

On our roadmap — we'll publish certification details here once verified.

🔵SOC 2 Type II

Planned — we'll publish audit progress here.

📚ISO 27001

Planned — we'll publish progress here.

🔐GDPR & UK GDPR

We build to GDPR principles and are formalising our compliance documentation — we'll publish details here as each item is completed.

Vulnerability reporting

Found a security issue? Tell us privately so we can fix it.

  • Email: info@hven.io
  • PGP key: available on request from info@hven.io — encrypted submissions welcomed.
  • Response: we aim to acknowledge reports quickly and will publish our formal response targets and safe-harbour terms here.

Sub-processors

The third-party services that help us deliver Hven, and what each one handles.

We're updating this list following our product's evolution — the complete list with regions is being finalised. Email info@hven.io with any questions about this list.

Sub-processorRoleRegion
MongoDBPrimary databaseConfirming — updated shortly
ResendTransactional email deliveryConfirming — updated shortly
AnthropicAI analysis for your checks and reportsConfirming — updated shortly
Moonshot AIAI answers for your weekly checks (the Kimi assistant) — receives the questions we ask, which include your business nameChina
CloudinaryLogo & image storageConfirming — updated shortly

We aim to notify customers in advance of any new sub-processor — we'll publish our formal notice period here. Subscribe to sub-processor updates to be notified.

Ready for your security review?

Email info@hven.io with your security questions — we'll answer them directly, and we're preparing a formal security pack.

Email our security team