Security
How workspaces are kept apart, where data lives, what runs in your browser, and what we have not built yet. Written to be checked rather than skimmed.
Last updated
One workspace cannot see another
Separation is enforced by the database, not by application code remembering to filter. Every table carrying customer data has PostgreSQL row-level security switched on — 116 tables at the time of writing — and the policies on them resolve which workspace the current session belongs to before any row is returned.
That matters because it fails safe. A query written wrongly, or a new screen that forgets a filter, returns nothing rather than somebody else’s records. Owner-only actions are gated the same way, in the database, rather than by hiding a button.
Signing in
There are no passwords. You sign in with Google, or with a single-use link emailed to you, and sessions are held in cookies your browser will not hand to JavaScript. Nothing to reuse across sites, nothing to leak in a breach elsewhere, nothing for us to store badly.
A person only reaches a workspace if an owner of that workspace has invited their email address. An account with no seat is refused at the door and told so plainly.
Where your data is
Harvio runs on Vercel in Dublin and stores data in Supabase (PostgreSQL) in the EU. Traffic is HTTPS only — the site sends an HSTS header instructing browsers to refuse a plaintext connection for two years, including on subdomains. Our hosting and database providers encrypt data at rest; the specifics are theirs to state and are published in their own documentation.
What runs in your browser
Nothing that is not ours. Harvio loads no third-party scripts, no analytics, no tag manager, no session recorder, no advertising pixel and no external fonts. This is not a policy anybody has to remember: a check in our build fails if a script or stylesheet from another host appears anywhere in the codebase.
Consequently there are exactly two cookies. One keeps you signed in. One remembers whether you chose the light or dark theme, and it is scoped so tightly that your browser never sends it on a page a customer of yours would open.
Every response carries a Content Security Policy. Inside the workspace, where your data is read, that policy is issued fresh for each request and permits only the scripts that response vouched for — so a script injected into a page does not run.
Deleting things, and meaning it
Deleted records stay restorable for a window each workspace sets — 90 days by default — and are then erased, with their files removed from storage. What survives is the record that something happened, not its contents.
Who else touches your data
These are the services Harvio passes data to in order to work. Two deserve to be read carefully rather than scanned, and are marked.
| Service | What it does | What it sees |
|---|---|---|
| Supabase | Database, sign-in and file storage | Everything you store in Harvio |
| Vercel | Hosting and delivery | Request metadata; no application data at rest |
| Resend | Sending and receiving email | Message content and addresses |
| Google (Calendar API) | Only when a person connects their calendar: reading when they are busy, writing their bookings | Free/busy of the calendars they tick; the bookings Harvio writes, and nothing else in the calendar |
| Meta | The WhatsApp Business channel, if you connect one | Message content and phone numbers |
| Anthropic ⚠ | Drafting inbox replies from your help centre | The conversation being answered, and your published articles |
| OpenAI ⚠ | Transcribing voice comments left on demos | The audio of that comment |
| Slack | Notifications, if you connect it | The content of the notification |
| HubSpot | Two-way sync, if you connect it | Contact and deal records you sync |
⚠ The two that involve AI. When a customer writes in, Harvio drafts a suggested reply from your published articles, and doing that sends the conversation to Anthropic. Every workspace starts on draft only — a person reads and sends, and nothing goes out unattended unless an owner deliberately changes that on the Inbox settings screen. Voice comments left on demos are transcribed by OpenAI. Neither is used to train anybody’s model, and both can be turned off; if you would rather they were off for your workspace, say so and we will do it.
What we do not have
Harvio is young and small, and it is more useful to say this plainly than to leave you to find out.
There is no SOC 2 report and no ISO 27001 certificate. There has been no third-party penetration test. There is no bug bounty programme. We do not have a 24-hour on-call rota, and we are not going to pretend a team of this size does.
What we do have is a small system with the boring parts done properly, a build that refuses changes which weaken the things described on this page, and the willingness to answer a specific question specifically. If your review needs something here that does not exist yet, ask — a straight answer costs you less than a discovery later.
Telling us about a problem
If you believe you have found a vulnerability, please tell us before telling anyone else, and give us a reasonable chance to fix it. We will confirm we have read it, keep you posted while it is open, and credit you if you would like to be credited.
Reach us through your usual contact at Harvio. A dedicated security address is on the list and is not live yet — see Privacy for how we handle what you send.