Security

Your data security is our foundation.

Halyo is built with security at every layer. Your organizational memory is yours alone โ€” encrypted, isolated, and under your control.

๐Ÿ”’

Encryption in Transit

All data transmitted between your tools and Halyo is encrypted using TLS 1.3, the latest transport layer security protocol.

๐Ÿ›ก๏ธ

Encryption at Rest

All stored data, including Odin's organizational memory, is encrypted using AES-256 encryption at rest.

๐Ÿ—๏ธ

Tenant Isolation

Each organization's data is logically isolated. Odin's memory for your organization is never accessible to other tenants.

๐Ÿ”‘

Access Controls

Role-based access controls (RBAC) ensure that only authorized team members can access specific features and data within your organization.

๐Ÿ“‹

Reasoning Audit Trail

Every autonomous decision made by our agents includes a full reasoning trace โ€” a human-readable explanation of what the agent decided and why.

โš™๏ธ

Tiered Autonomy Controls

You control the level of autonomy our agents have. Start with read-only mode and graduate to full autonomous execution when trust is earned.

Infrastructure Security

Halyo is hosted on enterprise-grade cloud infrastructure with automated backups, redundancy across multiple availability zones, and continuous monitoring. Our infrastructure is regularly audited and updated to address emerging threats.

Third-Party Integrations

When you connect platforms like Slack, GitHub, Jira, or Notion, Halyo accesses data through official API connections using OAuth 2.0 authentication. We request only the minimum permissions necessary to provide the Services. You can revoke access to any connected platform at any time.

Data Handling Practices

  • We never sell your data to third parties
  • Organizational data is never used to train general AI models
  • You can request full data export or deletion at any time
  • Data processing agreements (DPAs) are available for enterprise customers

Compliance

We are committed to meeting the highest security standards. Our current compliance posture includes GDPR compliance for handling personal data of EU residents, with additional certifications actively in progress. For specific compliance questions, contact our security team.

Responsible Disclosure

If you discover a security vulnerability, please report it responsibly to security@halyo.pro. We take all reports seriously and will respond within 48 hours.

Questions?

For security-related inquiries, contact us at security@halyo.pro.