HavaraPrivate by invitation

Havara: Security Overview

Effective October 6, 2026

This is a plain-English summary of how Havara protects community data, written so that boards, management companies, and other buyers can understand our security posture without reading the source code. It describes the product as it is built today, not aspirations. Where a control is optional or not yet in place, we say so plainly.

Havara is a multi-tenant mobile app (iOS and Android, built on Expo / React Native) with a web console, for HOA and residents' communities. One person can belong to several communities and switch between them. The backend is a hosted Supabase project (Postgres database, authentication, file storage, and serverless Edge Functions). Anyone can create a bare account, but an account alone grants access to nothing: joining a community requires a board-issued invite or an approved join request. The product is invitation-only at the community layer.

Questions about this document: privacy@havara.app.


Architecture: multi-tenant with Row-Level Security on every table

Havara runs every community on shared infrastructure (a single Postgres database), and keeps communities separated logically rather than on separate servers. The separation is enforced in the database itself:

Authentication: email + password, PKCE reset, session storage

Encryption: in transit and at rest

Data isolation: RLS plus community scoping

Isolation is not a single feature; it is the combination of the controls above:

Backups and recovery

Access control: board capabilities and least privilege

AI safety: documents-only, permission-filtered, guardrails

The AI "Ask" tab answers questions from a single community's own governing documents (CC&Rs, bylaws, rules, minutes, budgets, policies). It is built to be constrained, not open-ended:

Account deletion and data export

Account deletion and the personal data export are available in-app and act only on the requesting user. The community record export is for a community's administrators and is described at the end of this section.

Subprocessor management

Havara uses a small set of third-party services ("subprocessors") to run. The list below reflects what is actually wired into the product. Two entries (PostHog, and TypeSafe) do nothing today: PostHog unless explicitly configured, TypeSafe until its activation is approved. Every other entry in the table below is live and processing today. The table covers the vendors wired into the app itself; the canonical list, read against the app on 2026-09-25, is the Subprocessor List, which also covers Stripe (community billing) and Cloudflare (DNS, TLS, CDN, and hosting for the web console and marketing site).

SubprocessorWhat it doesData it seesRegion
SupabasePrimary backend: database, auth, file storage, Edge Functions, push orchestrationAll account data, memberships, user-generated content, documents and embeddings, AI Ask history, push tokens, notification preferences, audit/moderation records; Supabase's own request and sign-in logs (each request's IP address, user agent and the approximate location derived from it, with the member's user id when signed in and the email address on sign-in events, kept 7 days)Hosted Supabase project in the United States, region us-east-2 (US East / Ohio)
OpenAIText embeddings for Ask search, and the moderation service every Ask question is sent to before it is answered (a moderation call that times out or errors lets the question through rather than blocking it). Does not perform OCR; scanned PDFs go to AWS Textract (see the AWS row). (OpenAI does not generate answers or thread titles; titles are derived on the device with no AI call.)Document text, in chunks, when a document is indexed; and the member's question text, sent twice: once to the moderation endpoint and once to the embeddings endpoint, prefixed on a follow-up by the previous question in that thread. Not the retrieved excerpts, which go to Anthropic. No account identifiers in the request bodyUS-based API (api.openai.com)
Amazon Web ServicesOptical character recognition of scanned / image-only PDFs, via Amazon Textract's asynchronous plain-text detection (StartDocumentTextDetection). The PDF is copied to a private, encrypted, public-access-blocked S3 bucket for the duration of the scan and Havara deletes that staged copy after the scan, with a 1-day lifecycle rule as backstop. AWS's service terms allow it to store what Textract processes to provide and maintain the service, and would also let it use that content to improve Textract and other Amazon AI services, and keep some of it in another AWS region, unless an AWS AI services opt-out is in place; Havara has had that opt-out in place since September 23, 2026, covering Textract and every other AI service the policy covers. Documents that already contain selectable text are never sent.The bytes of scanned PDFs with no text layer, and the text recognized from them. No account or community identifiers are sent; the staged object's key carries the document's internal id.US-based API (textract.us-east-1.amazonaws.com, s3.us-east-1.amazonaws.com)
AnthropicGenerates the cited, documents-only Ask answer from retrieved excerptsThe question, prior turns in the thread, and the retrieved document excerpts; no account identifiers in the request bodyUS-based API (api.anthropic.com)
Expo (EAS / push)Delivers push notifications; also the build/distribution pipelineDevice push tokens and notification title/body/route (which may include message previews unless the member turns previews off)US-based service (exp.host)
AppleiOS app distribution (App Store / TestFlight) and APNs push deliveryApp distribution metadata and APNs push payloads relayed to iOS devicesUS-based service
GoogleAndroid push delivery through Firebase Cloud Messaging, and Android app distribution through Google PlayAndroid push payloads (the same title and body Expo receives, which may include message previews unless the member turns previews off) and app distribution metadataGoogle global infrastructure
TypeSafeConditional, currently disabled. If Havara switches it on, after 30 days' notice on the Subprocessor List, it would judge how well retrieved excerpts support an Ask answer; nothing is sent to it todayThe current question, at most the preceding question, and up to six retrieved excerpts; no account, community or document identifiersRegion to be confirmed before activation
Resend (LIVE since 2026-08-05)Sends email: sign-in emails, community invitations, member email about a member's own account, home and community, email copies of notifications a push did not reach, vendor quote-request relays, announcement email mirroring, and operator alerts. The Subprocessor List has the full listRecipient email addresses and what each email says: for example the community name and invite code; vendor contact details and, on a quote relay, the requesting resident's phone number and email address; announcement content mirrored to member emailUS-based services (api.resend.com, and smtp.resend.com for sign-in emails)
PostHog (optional)Product analytics. Double-gated: requires both an analytics key (not set) and the individual member's in-app opt-in (default off, fail-closed)Event names with non-PII properties (ids, enums, counts) and a distinct user id; by enforced rule, no email, phone, push tokens, or message bodiesPostHog US cloud by default; EU/self-hosted host is configurable
Sentry (LIVE since 2026-08-26)Crash and error reporting over HTTP, switched on in every production build of the app. Covers uncaught JavaScript errors via a global handler and the errors the app catches and forwards itself. No native SDK, so no automatic breadcrumbs, no performance traces, no device fingerprintingThe error type and message; the stack trace when a real Error was thrown; the event level, environment and release; a caller-supplied call-site scope and context object; the signed-in account's Supabase user id; the approximate location (city, region and country) Sentry derives from the IP address each report arrives from, kept with the report; and, from app versions that do not ask Sentry not to keep it, possibly that IP address, which Sentry keeps only while its project setting against storing IP addresses is off (not yet checked against a stored event). Never message bodies, email, phone or push tokensSentry US ingest endpoint (o4511541325004800.ingest.us.sentry.io)

How we manage this list:

Certifications and roadmap

We want to be precise here, because security claims are easy to inflate.

We deliberately avoid marketing language like "bank-grade," "military-grade," or "unhackable." No system is perfectly secure. What we offer instead is the specific, verifiable set of controls described above, and an honest account of where we are on the path to formal certification.


Provider: Havara LLC, a Georgia limited liability company, 525 Tribble Gap Rd, P.O. Box 724, Cumming, GA 30040 Security contact: privacy@havara.app