Security
Your data security is our foundation.
Halyo is built with security at every layer. Your organizational memory is yours alone โ encrypted, isolated, and under your control.
Encryption in Transit
All data transmitted between your tools and Halyo is encrypted using TLS 1.3, the latest transport layer security protocol.
Encryption at Rest
All stored data, including Odin's organizational memory, is encrypted using AES-256 encryption at rest.
Tenant Isolation
Each organization's data is logically isolated. Odin's memory for your organization is never accessible to other tenants.
Access Controls
Role-based access controls (RBAC) ensure that only authorized team members can access specific features and data within your organization.
Reasoning Audit Trail
Every autonomous decision made by our agents includes a full reasoning trace โ a human-readable explanation of what the agent decided and why.
Tiered Autonomy Controls
You control the level of autonomy our agents have. Start with read-only mode and graduate to full autonomous execution when trust is earned.
Infrastructure Security
Halyo is hosted on enterprise-grade cloud infrastructure with automated backups, redundancy across multiple availability zones, and continuous monitoring. Our infrastructure is regularly audited and updated to address emerging threats.
Third-Party Integrations
When you connect platforms like Slack, GitHub, Jira, or Notion, Halyo accesses data through official API connections using OAuth 2.0 authentication. We request only the minimum permissions necessary to provide the Services. You can revoke access to any connected platform at any time.
Data Handling Practices
- We never sell your data to third parties
- Organizational data is never used to train general AI models
- You can request full data export or deletion at any time
- Data processing agreements (DPAs) are available for enterprise customers
Compliance
We are committed to meeting the highest security standards. Our current compliance posture includes GDPR compliance for handling personal data of EU residents, with additional certifications actively in progress. For specific compliance questions, contact our security team.
Responsible Disclosure
If you discover a security vulnerability, please report it responsibly to security@halyo.pro. We take all reports seriously and will respond within 48 hours.
Questions?
For security-related inquiries, contact us at security@halyo.pro.
