HavnSight Intelligence

Learn more
Trust and security

Speed without compromise.

Security is built into the HavnSight architecture, delivery pipeline and daily operations, so your teams can move fast on a platform they can trust.

Last updated: October 6, 2026

Encrypted in transit

HTTPS-only access with modern TLS and DNSSEC.

Encrypted at rest

Managed data services encrypt stored data.

One identity service

Products never handle passwords directly.

Infrastructure as code

Version-controlled, auditable configuration.

Our approach

Four principles guide every decision

01

Secure by design

A managed global edge platform keeps the attack surface small and removes server maintenance.

02

Defence in depth

Protections are layered across network, identity, application and data tiers.

03

Least privilege

People, services and automation receive only the access their role requires.

04

Continuous improvement

Controls are reviewed as the platform evolves, with independent validation added over time.

Architecture

One protected edge in front of every application

Applications run on Cloudflare's global network. Encrypted connections end at the edge, and integrations with identity, bot protection, email and regional services run over HTTPS.

Browser
Customer
Cloudflare edgeTLS · DNSSEC · DDoS mitigation
Marketing site
www.havnsight.com
HavnSight Identity
id.havnsight.com
Account app
account.havnsight.com
Edge API
edge-api.havnsight.com
Managed data stores
Encrypted at rest · secrets store
Identity engineThird party
Open source
Bot protectionThird party
Cloudflare Turnstile
Transactional emailThird party
Mailgun
Regional backends
Per-region services
Every public request passes the Cloudflare edge before it reaches an application.
Controls

Protection at every layer

Identity and access

  • Sign-in through HavnSight Identity, one service across every product
  • New workspaces created only after work-email verification
  • Public forms protected against automated abuse
  • Narrowly scoped credentials for automation and deployment

Data protection

  • Encryption in transit, with HTTP Strict Transport Security on public sites
  • Encryption at rest on managed data services
  • Secrets held in a managed store, never in source code
  • Temporary data configured to expire automatically

Application security

  • Automated linting, type-checking and build verification on every change
  • Strict schema validation of every public API request
  • Cross-origin access limited to HavnSight domains
  • Industry-standard browser security headers

Infrastructure and monitoring

  • Network, DNS and platform settings defined as code
  • DDoS mitigation on Cloudflare's global network
  • Platform and application activity logged
  • Alerts on critical operational failures
HavnSight Intelligence

AI on your terms. Your model, your key.

HavnSight Intelligence is the optional AI layer built into the platform, designed to operate within the same identity, encryption and access controls as everything else in HavnSight.

Bring Your Own Key for a supported provider
OpenAI, Anthropic or local models
A local model keeps prompts on infrastructure you control

Security reviews

We complete customer security questionnaires, share the full security whitepaper and walk your team through any section.

Request a review

Report a vulnerability

Email the details and steps to reproduce. Please allow reasonable time for a fix before public disclosure, and do not access data that is not your own. We will acknowledge your report and keep you informed.

security@havnsight.com