Tenant isolation
Every organization is isolated with Supabase Postgres Row-Level Security, app-side org checks, and service-role writes limited to server-side workflows.
HAPSecure is operated by UNFETTEREDMIND LLC. This page explains how the app protects PHA notices, tenant/unit information, HAP payment records, proof photos, and audit materials while the product is in production beta.
Every organization is isolated with Supabase Postgres Row-Level Security, app-side org checks, and service-role writes limited to server-side workflows.
AI extraction is a draft. Users verify the source notice, deadline, and deficiency before anything becomes part of the compliance ledger.
Compliance events are appended to a SHA-256 hash chain, and source documents are stored in private WORM-style storage.
The app supports MFA/TOTP, AAL2 step-up enforcement, secure auth redirects, signup throttles, bot-trap handling, and Turnstile integration once keys are configured.
Data handled
The app stores the operational records a Section 8 landlord needs to respond to PHA notices and document cure work. Users should not upload unrelated sensitive records.
AI data use
HAPSecure uses AI to classify and extract information from documents that users submit to the app. Customer documents are not used for model training unless the customer explicitly opts in through a future written permission flow.
AI output remains a draft. A human reviewer must verify the PHA notice, deadline, unit, and deficiency before the result becomes a ledger event.
Support is available at support@hapsecure.app. Include the screen, approximate time, and workflow you were using. Do not send tenant PII by email unless HAPSecure requests it through a secure channel.
During beta, support targets are commercially reasonable rather than SLA-backed. Emergency housing, legal, or PHA-deadline questions must still go to your PHA or qualified counsel.
Subprocessors
Subprocessors are used only for hosting, storage, billing, monitoring, email, AI extraction, edge processing, or user-requested certified-mail workflows.
Database, Auth, private storage, and Row-Level Security.
Application hosting, serverless functions, deployment, and runtime headers.
Subscription billing, checkout, customer portal, and metered add-on events.
AI extraction of uploaded notices after users submit documents.
DNS, edge protection, Turnstile when enabled, email routing, and inbound Worker processing.
Transactional email provider for outbound app mail where configured.
Error monitoring and production diagnostics where configured.
Certified-mail letter creation only when a user explicitly requests that workflow.
HAPSecure keeps compliance records while an account is active and as needed for audit, security, legal, billing, or record-retention purposes. Users can export audit reports and evidence packets from the app.
Deletion requests can be sent to support@hapsecure.app. Some records may be retained where required for compliance evidence, fraud prevention, security, billing, or legal obligations.
HAPSecure will provide notice of confirmed security incidents as required by applicable law and customer terms. Final breach-notice language remains part of the limited-scope counsel review gate.