Your family's data deserves more than "trust us"

Haven was designed from day one to protect the most sensitive information a family has: wills, insurance, financial accounts, medical documents. Here's exactly how we do it, and why it's stronger than the cloud storage you use today.

AES-256
Encryption at rest
TLS 1.3
Encryption in transit
0
Data retained by AI
100%
Authenticated endpoints

More secure than Google Drive, Dropbox, or iCloud

Most cloud storage encrypts your files, but anyone at the company with admin access can still see them. Haven adds row-level data isolation, household-scoped access controls, and AI that processes in isolation and discards immediately. Your documents are not just stored securely. They are architecturally inaccessible to anyone but you.

Haven vs. typical cloud storage

Security isn't just encryption. It's architecture, access controls, and what happens with your data after you upload it.

Security Feature Haven Google Drive Dropbox iCloud
Encryption at rest AES-256 AES-256 AES-256 AES-256
Encryption in transit TLS 1.3 TLS 1.3 TLS 1.2+ TLS 1.2+
Row-level data isolation Yes No No No
Admin access to your files None Possible Possible Possible*
AI that discards data after use Yes Retained N/A Retained
Per-document vault lock Yes No Add-on No
Biometric app lock Yes No No Device-level
Immutable audit log Yes Activity log Events log No
Data used for ad targeting Never Metadata No No
Row-level data isolation
Haven Yes Others No
Admin access to your files
Haven None Others Possible
AI discards data after use
Haven Yes Others Retained
Per-document vault lock
Haven Yes Others No
Biometric app lock
Haven Yes Others No
Immutable audit log
Haven Yes Others Limited
Data used for ad targeting
Haven Never Others Possible

Six layers of protection

Every layer is independently secure. Even if one layer were compromised, the others keep your data protected.

Encryption

Every API call uses TLS 1.3. Database storage uses AES-256, the same standard used by banks. Optional vault lock adds an additional layer for your most sensitive documents.

  • TLS 1.3 for all data in transit
  • AES-256 encryption at rest
  • Optional per-document vault lock
  • Secure key management with rotation

Architecture

Row-level security on every table. Every query is scoped to your household. Cross-household access is architecturally impossible. Not just policy, but code.

  • Row-level security on every table
  • Household-scoped data isolation
  • No cross-household access possible
  • Every endpoint requires authentication

AI Privacy

Alfred analyzes your documents in isolated, ephemeral processes. Content is immediately discarded. Nothing is stored, cached, or persisted. Never used to train AI models. Period.

  • Analysis in isolated, ephemeral processes
  • Content discarded immediately after processing
  • Never used to train AI models
  • No third-party data sharing
  • AI context scoped to your household only

Access Controls

Face ID and Touch ID for quick, secure access. Every document access is logged in an immutable audit trail that cannot be modified or deleted.

  • Biometric authentication (Face ID / Touch ID)
  • Secure session management
  • Immutable access audit log
  • Secure password reset via email verification

Household Sharing

Your spouse gets their own login with shared household access. Each person's Alfred chat history stays private. Invite codes expire after 30 days.

  • Individual logins, shared household data
  • Private chat history per user
  • Invite codes with 30-day expiration
  • Merge confirmation required by both parties

Device Security

Tokens stored in the iOS Keychain, Apple's hardware-backed secure enclave. Biometric app lock keeps your data protected even on an unlocked phone.

  • iOS Keychain for token storage
  • Biometric app lock
  • No sensitive data in local storage
  • Secure credential handling

What we will never do

These aren't policies that can be changed with a terms update. They are architectural decisions baked into how Haven is built.

Sell your data to anyone, ever
Share data with third parties
Show you advertisements
Use your documents for AI training
Store passwords in plain text
Access your data without authentication
Retain document content after AI analysis
Allow cross-household data access
Track your behavior for profiling

What we will never do

Architectural decisions, not policies.

Sell your data to anyone, ever
Share data with third parties
Show you advertisements
Use your documents for AI training
Store passwords in plain text
Access data without authentication
Retain content after AI analysis
Allow cross-household access
Track behavior for profiling

Your data's journey through Haven

From the moment you upload a document to the moment Alfred answers your question, here's what happens.

1
Upload

Your document is encrypted with TLS 1.3 during upload, then stored with AES-256 encryption in Google Cloud Storage. The file is tagged to your household and inaccessible to any other account.

2
Analysis

Alfred reads your document in an isolated, ephemeral process. It extracts dates, identifies the type, and returns structured data. The document content is immediately discarded from AI memory. Nothing is cached.

3
Storage

Only the extracted metadata (dates, type, summary) is stored alongside your encrypted file. When you ask Alfred a question, it references this metadata, never re-reading the full document through AI.

Have a security question?

We take this seriously. If you have questions about how your data is handled, reach out and we'll give you a straight answer.

support@havenhome.dev