Security

How workspaces are kept apart, where data lives, what runs in your browser, and what we have not built yet. Written to be checked rather than skimmed.

Last updated

One workspace cannot see another

Separation is enforced by the database, not by application code remembering to filter. Every table carrying customer data has PostgreSQL row-level security switched on — 116 tables at the time of writing — and the policies on them resolve which workspace the current session belongs to before any row is returned.

That matters because it fails safe. A query written wrongly, or a new screen that forgets a filter, returns nothing rather than somebody else’s records. Owner-only actions are gated the same way, in the database, rather than by hiding a button.

Signing in

There are no passwords. You sign in with Google, or with a single-use link emailed to you, and sessions are held in cookies your browser will not hand to JavaScript. Nothing to reuse across sites, nothing to leak in a breach elsewhere, nothing for us to store badly.

A person only reaches a workspace if an owner of that workspace has invited their email address. An account with no seat is refused at the door and told so plainly.

Where your data is

Harvio runs on Vercel in Dublin and stores data in Supabase (PostgreSQL) in the EU. Traffic is HTTPS only — the site sends an HSTS header instructing browsers to refuse a plaintext connection for two years, including on subdomains. Our hosting and database providers encrypt data at rest; the specifics are theirs to state and are published in their own documentation.

What runs in your browser

Nothing that is not ours. Harvio loads no third-party scripts, no analytics, no tag manager, no session recorder, no advertising pixel and no external fonts. This is not a policy anybody has to remember: a check in our build fails if a script or stylesheet from another host appears anywhere in the codebase.

Consequently there are exactly two cookies. One keeps you signed in. One remembers whether you chose the light or dark theme, and it is scoped so tightly that your browser never sends it on a page a customer of yours would open.

Every response carries a Content Security Policy. Inside the workspace, where your data is read, that policy is issued fresh for each request and permits only the scripts that response vouched for — so a script injected into a page does not run.

Deleting things, and meaning it

Deleted records stay restorable for a window each workspace sets — 90 days by default — and are then erased, with their files removed from storage. What survives is the record that something happened, not its contents.

Who else touches your data

These are the services Harvio passes data to in order to work. Two deserve to be read carefully rather than scanned, and are marked.

ServiceWhat it doesWhat it sees
SupabaseDatabase, sign-in and file storageEverything you store in Harvio
VercelHosting and deliveryRequest metadata; no application data at rest
ResendSending and receiving emailMessage content and addresses
Google (Calendar API)Only when a person connects their calendar: reading when they are busy, writing their bookingsFree/busy of the calendars they tick; the bookings Harvio writes, and nothing else in the calendar
MetaThe WhatsApp Business channel, if you connect oneMessage content and phone numbers
Anthropic ⚠Drafting inbox replies from your help centreThe conversation being answered, and your published articles
OpenAI ⚠Transcribing voice comments left on demosThe audio of that comment
SlackNotifications, if you connect itThe content of the notification
HubSpotTwo-way sync, if you connect itContact and deal records you sync

⚠ The two that involve AI. When a customer writes in, Harvio drafts a suggested reply from your published articles, and doing that sends the conversation to Anthropic. Every workspace starts on draft only — a person reads and sends, and nothing goes out unattended unless an owner deliberately changes that on the Inbox settings screen. Voice comments left on demos are transcribed by OpenAI. Neither is used to train anybody’s model, and both can be turned off; if you would rather they were off for your workspace, say so and we will do it.

What we do not have

Harvio is young and small, and it is more useful to say this plainly than to leave you to find out.

There is no SOC 2 report and no ISO 27001 certificate. There has been no third-party penetration test. There is no bug bounty programme. We do not have a 24-hour on-call rota, and we are not going to pretend a team of this size does.

What we do have is a small system with the boring parts done properly, a build that refuses changes which weaken the things described on this page, and the willingness to answer a specific question specifically. If your review needs something here that does not exist yet, ask — a straight answer costs you less than a discovery later.

Telling us about a problem

If you believe you have found a vulnerability, please tell us before telling anyone else, and give us a reasonable chance to fix it. We will confirm we have read it, keep you posted while it is open, and credit you if you would like to be credited.

Reach us through your usual contact at Harvio. A dedicated security address is on the list and is not live yet — see Privacy for how we handle what you send.