Security & Compliance at Hven
Your business data and AI-visibility results, encrypted at rest and in transit. Built to satisfy your security review on the first pass.
GDPR compliance
We process the business information you give us and the public AI answers we collect about your brand — nothing more.
- Data subject rights: access, rectification, erasure, portability, and objection — all responded to within 30 days.
- Privacy requests: contact us at the address on this page — we're finalising our dedicated privacy contact.
- Supervisory authority: UK ICO (Information Commissioner's Office) is our lead authority for the UK.
Data protection
Defence in depth at every layer — transport, storage, and access.
All traffic between your browser, the dashboard, and our backend is encrypted in transit with TLS (HTTPS everywhere).
All databases use AES-256 encryption at rest. Per-tenant data is logically isolated — every read and write is scoped to the owning tenant at the data-access layer.
Encrypted backups are managed through our database provider. We're confirming retention specifics and will publish them here.
Our application and database are not exposed directly to the public internet beyond the product's own endpoints; administrative access is restricted to the founding team and protected by strong authentication.
Data location
Your account data is stored with the providers listed below. To run your weekly checks, the questions we ask — which include your business name and market — are sent to the AI providers in the sub-processor table, some of which operate outside the UK/EU, including in the United States and China. We list every one of them plainly below, and we're finalising the full transfer-safeguard details for each as part of updating this page.
- Hosting: our application runs on Railway. We're confirming and will publish the specific hosting region here.
Access controls
Who can do what, and how we prove it after the fact.
TOTP-based two-factor authentication available on every account.
Sessions are signed JSON Web Tokens with short-lived access tokens — they expire after minutes, not days.
Role-based permissions with feature-level gating. Platform-admin capabilities are gated by a dedicated platform-admin role that ordinary tenant accounts do not carry.
Sensitive account and team actions — role changes, password and 2FA changes, invites, API key issuance — are written to an append-only audit log.
What Hven processes
Hven checks how AI assistants talk about your business. There is no tracking script, no plugin, and no code on your website.
- Business information you provide. Your brand name, website and profile details — used to run your weekly checks.
- Public AI answers. The responses AI assistants give to the questions your customers ask, collected from the outside — the same way your customers see them.
- Your account data. Sign-in details and preferences for the people on your team.
- Nothing about your website's visitors. Hven does not run on your website, so it collects no data about the people who visit it.
- No cross-tenant mixing. Each tenant's data is its own walled garden — we never join one customer's data with another's.
Certifications & roadmap
What we have, and what we're working towards.
On our roadmap — we'll publish certification details here once verified.
Planned — we'll publish audit progress here.
Planned — we'll publish progress here.
We build to GDPR principles and are formalising our compliance documentation — we'll publish details here as each item is completed.
Vulnerability reporting
Found a security issue? Tell us privately so we can fix it.
- Email: info@hven.io
- PGP key: available on request from info@hven.io — encrypted submissions welcomed.
- Response: we aim to acknowledge reports quickly and will publish our formal response targets and safe-harbour terms here.
Sub-processors
The third-party services that help us deliver Hven, and what each one handles.
We're updating this list following our product's evolution — the complete list with regions is being finalised. Email info@hven.io with any questions about this list.
| Sub-processor | Role | Region |
|---|---|---|
| MongoDB | Primary database | Confirming — updated shortly |
| Resend | Transactional email delivery | Confirming — updated shortly |
| Anthropic | AI analysis for your checks and reports | Confirming — updated shortly |
| Moonshot AI | AI answers for your weekly checks (the Kimi assistant) — receives the questions we ask, which include your business name | China |
| Cloudinary | Logo & image storage | Confirming — updated shortly |
We aim to notify customers in advance of any new sub-processor — we'll publish our formal notice period here. Subscribe to sub-processor updates to be notified.