Security

How we protect the data on our platform

Project data and financial models are sensitive by nature. We keep the platform invite-only and apply standard, well-understood security practices across infrastructure, access control, and data handling.

Security Overview

Encryption

Data is encrypted in transit using TLS 1.2+ and at rest by our managed infrastructure providers.

Invite-Only Access

There is no open registration. Accounts exist only for invited collaborators, with role-based permissions.

Managed Infrastructure

Hosted on established cloud providers that maintain their own independent security certifications.

Scoped Workspaces

Company workspaces are isolated; members only see the projects and data they are invited to.

Access Control & Authentication

  • Invitation-only sign-in — accounts cannot be self-created
  • Authentication via established identity providers with database-backed sessions
  • Role-based access within each workspace (admin, editor, viewer)
  • Access to a workspace requires an accepted membership in that workspace
  • Session expiry and sign-out controls

Infrastructure & Data Handling

  • Application and database hosted on established managed cloud providers
  • All traffic served over HTTPS with TLS 1.2 or higher
  • Encryption at rest provided by our infrastructure providers
  • Automated backups with point-in-time recovery
  • Workspace-level data isolation enforced in the application layer
  • We do not store payment card data — there are no self-serve purchases on the platform

Data Protection & Privacy

  • We do not sell user data
  • Data processing agreement available — see our DPA
  • Account and data deletion on request — see Account & Data Deletion
  • Data retention aligned with legal requirements

Security Best Practices for Users

  • Protect the email account you use to sign in — it is your identity on the platform
  • Regularly review who has access to your workspaces and projects
  • Keep your browser and devices updated
  • Be cautious of phishing attempts — we'll never ask for your credentials via email
  • Log out when using shared computers

Security Incident Response

In the event of a security incident, we will investigate and contain it, notify affected users without undue delay, and take measures to prevent recurrence.

Responsible Disclosure

If you believe you have found a security vulnerability in our platform, please report it to us privately so we can address it before public disclosure.

Report Security Issues

  • Email: support@hectares.ai with the subject "Security Report"
  • Please include: description, steps to reproduce, and potential impact
  • We will acknowledge and investigate all good-faith reports

Security Contact

Security & Support: support@hectares.ai

Privacy & Legal: legal@hectares.ai

Mailing Address:
Hectares LLC
30 N Gould St Ste N
Sheridan, WY 82801
United States