Trust Center

Security and data practices for compliance records.

HAPSecure is operated by UNFETTEREDMIND LLC. This page explains how the app protects PHA notices, tenant/unit information, HAP payment records, proof photos, and audit materials while the product is in production beta.

Tenant isolation

Every organization is isolated with Supabase Postgres Row-Level Security, app-side org checks, and service-role writes limited to server-side workflows.

Human review before ledger commit

AI extraction is a draft. Users verify the source notice, deadline, and deficiency before anything becomes part of the compliance ledger.

Tamper-evident records

Compliance events are appended to a SHA-256 hash chain, and source documents are stored in private WORM-style storage.

Account protection

The app supports MFA/TOTP, AAL2 step-up enforcement, secure auth redirects, signup throttles, bot-trap handling, and Turnstile integration once keys are configured.

Data handled

What HAPSecure stores

The app stores the operational records a Section 8 landlord needs to respond to PHA notices and document cure work. Users should not upload unrelated sensitive records.

  • PHA notices, inspection letters, and portal exports
  • Unit, landlord, tenant, rent, and HAP split-ledger data
  • Deficiency, cure-deadline, review, and audit-record data
  • Repair proof photos, timestamps, notes, and optional GPS metadata
  • Team-member account, role, billing, and notification settings

AI data use

Customer documents are not training material

HAPSecure uses AI to classify and extract information from documents that users submit to the app. Customer documents are not used for model training unless the customer explicitly opts in through a future written permission flow.

AI output remains a draft. A human reviewer must verify the PHA notice, deadline, unit, and deficiency before the result becomes a ledger event.

Support expectations

Support is available at support@hapsecure.app. Include the screen, approximate time, and workflow you were using. Do not send tenant PII by email unless HAPSecure requests it through a secure channel.

During beta, support targets are commercially reasonable rather than SLA-backed. Emergency housing, legal, or PHA-deadline questions must still go to your PHA or qualified counsel.

Subprocessors

Services that help run HAPSecure

Subprocessors are used only for hosting, storage, billing, monitoring, email, AI extraction, edge processing, or user-requested certified-mail workflows.

Supabase

Database, Auth, private storage, and Row-Level Security.

Vercel

Application hosting, serverless functions, deployment, and runtime headers.

Stripe

Subscription billing, checkout, customer portal, and metered add-on events.

Anthropic

AI extraction of uploaded notices after users submit documents.

Cloudflare

DNS, edge protection, Turnstile when enabled, email routing, and inbound Worker processing.

Resend

Transactional email provider for outbound app mail where configured.

Sentry

Error monitoring and production diagnostics where configured.

Lob

Certified-mail letter creation only when a user explicitly requests that workflow.

Retention and export

HAPSecure keeps compliance records while an account is active and as needed for audit, security, legal, billing, or record-retention purposes. Users can export audit reports and evidence packets from the app.

Deletion requests

Deletion requests can be sent to support@hapsecure.app. Some records may be retained where required for compliance evidence, fraud prevention, security, billing, or legal obligations.

Incident notice

HAPSecure will provide notice of confirmed security incidents as required by applicable law and customer terms. Final breach-notice language remains part of the limited-scope counsel review gate.

© 2026 HAPSecure. HAPSecure is workflow software, not legal advice. Verify deadlines and proof requirements with your PHA.Updated June 29, 2026.