Isolation
- One workspace per client. Each client is its own workspace with its own data. Nothing one workspace learns reaches another.
- Segregated storage. Workspace records and uploaded files are stored and served per workspace, not in a shared pool you filter by client.
- Role-based access on every request. Membership and role are checked when a request is served, not just when a page is drawn. Three workspace roles: Administrator, User and a dedicated Client role.
- The Client role sees only what you switch on. Client View is off by default. You choose section by section what a client can see, preview the workspace as the client would, then invite them.
- Experiments are sandboxed. A positioning scenario runs in its own copy of the workspace and changes nothing in the live one.
Account security
- Hashed passwords. Passwords are stored hashed, never in clear text.
- Revocable API keys. Keys for the read-only profile API are created and revoked by you, in the workspace.
- Sessions can be ended. Sign-in tokens are revoked on sign-out.
- No account enumeration. A password reset request answers the same way whether or not the address has an account.
Publishing controls
- Domain verification first. Nothing about a client goes public until the client's domain has been verified as theirs.
- A strict whitelist of public fields. The public profile is built from a fixed list of fields. Everything else in the workspace stays private by construction, not by omission.
- Nothing is published until you publish it. The public profile and the client's agent are drafts until you choose to publish, and you can unpublish.
- Opt out of listing. A published profile can be kept out of any listing, so it is readable at its own address but not browsable.
Data handling
- Public sources only. A workspace is built from the client's site, their competitors' sites and the open web. Nothing from inside the client is needed, so the analysis is free of internal bias and safe to share.
- Uploads stay in the workspace. A brief, a deck or a document you upload is used for that client's workspace and nowhere else.
- Deletion that sticks. Deleting a workspace removes it from every view at once and a cleanup pass purges its records. Deleting a file deletes the file.
- Deletable agent history. Conversations with a workspace's agent can be deleted from the workspace.
Enterprise
Single sign-on and custom data separation policies are in early access for Enterprise, as listed on the pricing page. Write to hello@haycion.com to talk about a firm-wide setup.
What this page does not claim
Haycion does not hold a security certification and does not claim one here. If a control you need is not on this page, ask before you assume it exists.
Haycion