These measures describe the implemented state of the HeyDiane platform,
not aspirations. They are reviewed with every architecture change and at
least quarterly.
1. Encryption
- In transit: TLS for all connections — browser to application,
application to every sub-processor API. HSTS (max-age 1 year,
includeSubDomains, preload) prevents protocol downgrade.
- At rest: database including backups encrypted by the hosting
provider; every object in audio storage encrypted (AES-256) by the storage
provider.
- Application level: OAuth credentials of connected cloud accounts
are additionally encrypted in the database (Fernet: AES-128-CBC + HMAC)
with the key held outside the database in the runtime environment;
key rotation supported. Passwords are hashed with Argon2id. API tokens are
stored only as SHA-256 hashes.
- Internal traffic between application, database and queue runs in
the hosting provider's private network within one EU region.
2. Access Control (Zutritt/Zugang/Zugriff)
- Physical security is inherited from the EU data centers of the hosting
providers (ISO 27001 / SOC 2 certified operators).
- Authentication with verified email + Argon2id-hashed password or Google
sign-in; session cookies HttpOnly, Secure, SameSite.
- Authorization is enforced server-side on every request: workspace
membership and role capabilities are re-resolved per request, never taken
from the client.
- The operator backend uses a separate password session bound to an
explicit admin flag; product sessions can never open it.
- Database roles follow least privilege: the runtime role cannot alter
schema and is subject to forced row-level security.
3. Tenant Separation
- Every business table carries a tenant id; PostgreSQL row-level security
is enabled AND forced on all of them — a query outside a tenant context
returns nothing, including for the table owner.
- Background jobs re-validate tenant and object ownership before acting;
jobs with mismatched payloads are rejected and recorded.
- Storage keys are namespaced per tenant; audio is only reachable through
short-lived signed URLs (10 minutes) issued after an authorization check.
4. Pseudonymization and Data Minimization
- Queue messages carry opaque ids only — never content, never email
addresses.
- Email-import bookkeeping is scrubbed of sender, subject and filename
immediately after a successful import.
- AI sub-processors receive only what the function needs (audio for
transcription, transcript text for summaries); no account data is sent.
5. Deletion Concept
- Recording deletion removes rows (transcripts to the word level,
summaries, chat, citations), storage objects (audio, generated documents)
and processing bookkeeping via an auditable job — effective within seconds
of the user action.
- Workspace deletion additionally purges workspace chat, tags, ingest
addresses, connected cloud accounts including credentials, and API
tokens.
- Exports auto-delete after 7 days. Backups rotate within 7 days;
deletions are re-applied on any restore.
6. Integrity and Availability
- Jobs are durable database rows with retries and exponential backoff; a
reconciler re-dispatches lost or stale work every 5 minutes.
- Point-in-time database backups; storage is versioned at the provider
level; deployments are atomic with health checks.
- Original audio is immutable — the pipeline never modifies uploaded
objects.
7. Logging and Auditability
- Privacy-relevant actions (export, deletion requests, access changes,
provider failures) are written to an append-only audit table with actor,
object and timestamp.
- Application logs contain no conversation content and no credentials.
8. Organizational Measures
- Sub-processors only under Art. 28 agreements; the public list is
updated before a new provider processes data.
- Secrets live exclusively in the runtime environment configuration,
never in the code repository.
- Changes reach production through version control with automated test
suites covering authorization and cross-tenant denial paths.
- Data protection contact: info@heydiane.ai.