Trust
How we look after your data, your systems and your work
This page is for the security, privacy, legal and procurement teams who check a supplier before work starts. It lists what we commit to on every engagement, and each one is a commitment a small company can keep every time.
Last reviewed
For your vendor form
Supplier facts
Most of what a supplier form asks for is here. We'll send anything else in writing when you ask, before or with the proposal.
- Legal name
- Havihi Digital Inc.
- Incorporated
- Federally in Canada, in 2022.
- Where we work
- Remotely from Canada, taking on work across Canada and the United States.
- How we charge
- A fixed price or a fixed monthly fee, agreed in writing before work starts.
- Certifications
- We don't hold a formal security certification such as SOC 2 or ISO 27001.
- Security contact
- hello@havihi.digital, which our security.txt file also lists.
- Supplier forms
- Our registered office and other supplier details come in writing whenever you ask, and we'll complete your security questionnaire in writing.
- Genuine channels
- Our company website is havihi.digital, and Recordist's is recordist.app. We write only from addresses ending in @havihi.digital, or @recordist.app about Recordist.
On every engagement
What we commit to
Each line here is something we do on every engagement, whatever its size.
Your data stays where it is
We work inside your systems, with the access your team grants. We don't copy your data to our own computers unless you've agreed to it in writing. When a copy can't be avoided, we keep the smallest amount for the shortest time, then delete it and confirm that in writing. Where we can, we build and test with made-up or de-identified data.
Access
We ask only for the access the work needs. When the work ends, we send you a list of every access to remove.
AI services and models
We don't use your data to train any model. Your data goes only into AI services you've approved in writing, with retention and training switched off wherever the provider allows it.
Software and costs in your name
Any software, licences or AI usage your project needs is bought in your name, directly from the provider. We don't resell it or add a margin. If we ever have a commercial relationship with a tool we recommend, we'll tell you in writing before you decide.
People
Your proposal names everyone who'll work on your project. We don't bring in anyone else, including subcontractors, without your written agreement. Anyone who works on your project is bound by confidentiality terms at least as strict as ours with you.
Confidentiality
We'll sign a reasonable NDA before you share details. We never name a client in public unless they've agreed to it in writing, and we don't reuse your data or documents on anyone else's work.
Your code, and your way out
Your code lives in your repositories from the first commit, and what we build for you is yours once it's paid for. We document what we build, prefer open standards and keep runbooks current, so you can change supplier or bring the work in house at any time. Every engagement can be ended on the notice set out in its proposal, and we hand everything over when it ends.
Email to us is handled by a business email provider whose servers may be outside Canada. We use email to arrange the work, and we agree a safer way to share anything sensitive.
Accessibility
We aim for WCAG 2.2 at level AA on every screen people use, and we check with tools and by hand. Our accessibility statement shows how this site was tested and what's still to do.
No need to take our word for it
What you can check for yourself
- Our open-source Recordist gateway is public on GitHub (opens in a new tab). Its tests and security policy are there too, so you can read how we write code.
- Our method is written out in full on our approach page, including how each rule becomes a test.
- This site sets no cookies, runs no analytics and loads nothing from other companies, and our privacy page explains it.
- Our accessibility statement lists the checks we ran and the ones still to do.
Plainly
What we don't offer
We don't hold a formal security certification such as SOC 2 or ISO 27001. We don't offer round-the-clock support, we don't run your production systems on our own servers and we don't give legal advice. If you need any of these, we'll tell you what to look for elsewhere.
Security
Report a security problem
Write to hello@havihi.digital. Our security.txt file lists the same address.
Checking us for your organisation?
Send us your security questionnaire, or ask anything this page doesn't answer. We'll reply within two working days, in writing.
Send us your questionnaire Read the questions to ask before you hire us