Trust Center

Clears your security review on the first pass.

Habeo handles IT-asset data for higher-education institutions. Here is our security posture, the trust documents your CISO needs, and the compliance frameworks Habeo helps you track — stated plainly, including where we are still working.

Read our HECVAT responsesecurity@usehabeo.com

Security posture

Encryption everywhere

AES-256 at rest (Neon-managed Postgres + Vercel Blob); TLS 1.3 in transit with HSTS.

Multi-tenant isolation

Every row carries an organization_id; Postgres row-level security scopes every query and fails closed on missing tenant context.

Immutable audit log

Every mutation is written to an append-only audit log in the same transaction; the application database role has no UPDATE or DELETE on it.

SSO & MFA

SAML SSO via Clerk (Shibboleth-ready) with SCIM on the roadmap; MFA for administrative access.

HECVAT 2024 published

Full HECVAT 4.1.5 workbook plus a Lite narrative — download before our first call.

SOC 2 readiness

A live Trust Services Criteria self-assessment runs in-product; an independent Type I examination is targeted. Not yet certified — we say so plainly.

Trust documents

Compliance frameworks Habeo tracks in-product

Habeo ships live compliance dashboards that evaluate your institution’s posture against these frameworks using the evidence already in the platform — audit trail, settings, attestations, and asset state:

Data handling & legal

Questions security teams ask

Where is our data stored, and is it encrypted?

Data is stored in Neon-managed PostgreSQL and Vercel Blob, encrypted at rest with AES-256 and in transit with TLS 1.3. Habeo runs on Vercel's US infrastructure. Each customer's data is isolated by organization with Postgres row-level security.

Do you have a SOC 2 report?

Not yet. Habeo runs a SOC 2 Trust Services Criteria control self-assessment inside the product today, and is working toward an independent Type I examination followed by Type II. We publish a full HECVAT 2024 response (Lite + Full 4.1.5 workbook) now, and will not describe ourselves as SOC 2 certified until a report exists.

How does the AI assistant handle our data?

The assistant is opt-in per organization and disabled by default. It runs on Anthropic models via the Vercel AI Gateway, is budget-capped and per-user rate-limited, and every action it proposes requires human confirmation and is written to the immutable audit log. It reads only the scoped context needed to answer a question within the asking user's permissions and college-unit scope.

What happens to access when someone leaves?

Habeo tracks asset assignments against your HRIS. When a person is terminated, their held assets surface for recovery, and the compliance dashboards flag any terminated person who still holds an active assignment. SCIM-based automatic deprovisioning is on the identity roadmap.

Is Habeo accessible (WCAG / VPAT)?

Habeo is targeting WCAG 2.1 AA conformance, and a VPAT/ACR is in progress. We will publish it here when complete. If accessibility is a gating requirement for your procurement, tell us your timeline.

Can we get a DPA and your sub-processor list?

Yes. Our Data Processing Addendum and current sub-processor list are linked below, alongside the Terms of Service and SLA. Email security@usehabeo.com for a signed DPA.

Have a question not answered here? Email security@usehabeo.com.