Trust Center
Clears your security review on the first pass.
Habeo handles IT-asset data for higher-education institutions. Here is our security posture, the trust documents your CISO needs, and the compliance frameworks Habeo helps you track — stated plainly, including where we are still working.
Security posture
Encryption everywhere
AES-256 at rest (Neon-managed Postgres + Vercel Blob); TLS 1.3 in transit with HSTS.
Multi-tenant isolation
Every row carries an organization_id; Postgres row-level security scopes every query and fails closed on missing tenant context.
Immutable audit log
Every mutation is written to an append-only audit log in the same transaction; the application database role has no UPDATE or DELETE on it.
SSO & MFA
SAML SSO via Clerk (Shibboleth-ready) with SCIM on the roadmap; MFA for administrative access.
HECVAT 2024 published
Full HECVAT 4.1.5 workbook plus a Lite narrative — download before our first call.
SOC 2 readiness
A live Trust Services Criteria self-assessment runs in-product; an independent Type I examination is targeted. Not yet certified — we say so plainly.
Trust documents
HECVAT Response
Higher Education Community Vendor Assessment Toolkit — full 331-question HECVAT 4.1.5 workbook (XLSX) plus a 30-question Lite narrative summary.
SOC 2 Readiness Assessment
Phase 10 control inventory mapped against the Trust Services Criteria.
Scope 3 Attestation Footnote
Reference methodology text for citing Habeo as an IT asset lifecycle carbon data source in an annual sustainability, CDP, or SASB report — sources, GHG Protocol category mapping, confidence levels, and stated exclusions.
Compliance frameworks Habeo tracks in-product
Habeo ships live compliance dashboards that evaluate your institution’s posture against these frameworks using the evidence already in the platform — audit trail, settings, attestations, and asset state:
- GLBA Safeguards Rule — 16 CFR Part 314
- CMMC 2.0 — CUI handling — DFARS 252.204-7012 + CMMC 2.0 + NIST 800-171
- FERPA data locality — 20 USC 1232g
- HEOA compliance — 34 CFR 668.43(a)(10)
- Section 508 / WCAG 2.1 AA — 36 CFR 1194 + WCAG 2.1 AA
- State student-data privacy laws — Multi-state (CA, NY, IL, CO, TX seeded)
- SOC 2 (Trust Services Criteria) — AICPA TSP Section 100 (2017, rev. 2022)
Data handling & legal
- Privacy & data processing: see the Privacy Policy, Data Processing Addendum, and sub-processor list. FERPA-aware handling; no student education records of record.
- AI data handling: the assistant is opt-in per organization, human-confirmed, budget-capped, and fully audit-logged — details in the FAQ below.
- Accessibility: targeting WCAG 2.1 AA; a VPAT/ACR is in progress and will be published here.
- Contract & uptime: see the Terms of Service and SLA.
Questions security teams ask
Where is our data stored, and is it encrypted?
Data is stored in Neon-managed PostgreSQL and Vercel Blob, encrypted at rest with AES-256 and in transit with TLS 1.3. Habeo runs on Vercel's US infrastructure. Each customer's data is isolated by organization with Postgres row-level security.
Do you have a SOC 2 report?
Not yet. Habeo runs a SOC 2 Trust Services Criteria control self-assessment inside the product today, and is working toward an independent Type I examination followed by Type II. We publish a full HECVAT 2024 response (Lite + Full 4.1.5 workbook) now, and will not describe ourselves as SOC 2 certified until a report exists.
How does the AI assistant handle our data?
The assistant is opt-in per organization and disabled by default. It runs on Anthropic models via the Vercel AI Gateway, is budget-capped and per-user rate-limited, and every action it proposes requires human confirmation and is written to the immutable audit log. It reads only the scoped context needed to answer a question within the asking user's permissions and college-unit scope.
What happens to access when someone leaves?
Habeo tracks asset assignments against your HRIS. When a person is terminated, their held assets surface for recovery, and the compliance dashboards flag any terminated person who still holds an active assignment. SCIM-based automatic deprovisioning is on the identity roadmap.
Is Habeo accessible (WCAG / VPAT)?
Habeo is targeting WCAG 2.1 AA conformance, and a VPAT/ACR is in progress. We will publish it here when complete. If accessibility is a gating requirement for your procurement, tell us your timeline.
Can we get a DPA and your sub-processor list?
Yes. Our Data Processing Addendum and current sub-processor list are linked below, alongside the Terms of Service and SLA. Email security@usehabeo.com for a signed DPA.
Have a question not answered here? Email security@usehabeo.com.