Your data security is our top priority
We maintain the highest standards of security, compliance, and data privacy to ensure your financial data is always protected.
Security built in at every layer.
From encryption and access control to compliance and certifications — Haydn is engineered for the security standards your data demands.
Secure Cloud Hosting
The Haydn platform is hosted on enterprise cloud infrastructure, with customer data stored at rest on AWS infrastructure in the United Kingdom. Our infrastructure providers maintain industry-leading physical and network security and are independently certified against standards including ISO 27001 and SOC 2.
Learn more about AWS Security →Encryption in Transit and at Rest
All data transmitted between clients, servers, and external services is protected using Transport Layer Security (TLS) encryption (HTTPS), and customer data is encrypted at rest with AES-256. This prevents unauthorised interception, eavesdropping, and tampering with your sensitive information.
Tenant Isolation and Data Protection
Multiple layers of isolation and hardening protect your most sensitive information:
- Row-level security enforced at the database layer, isolating every customer's data
- Memory-hard cryptographic hashing for all passwords and credentials
- Strict separation of production data from development and test environments
Access Control and Authentication
Multi-layered access controls protect your data from unauthorised access:
- Mandatory two-factor authentication (2FA) for all users
- Sign in with Google or Microsoft (OAuth 2.0)
- Invite-only workspaces — accounts are created by invitation only
- Role-Based Access Control (RBAC) ensuring least-privilege access
- Comprehensive audit logging and monitoring
Compliance and Certification
Our information security management system (ISMS) is built on recognised international standards:
- ISO 27001:2022 certification and SOC 2 Type II attestation in progress
- Regular independent penetration testing
- Continuous, automated compliance monitoring through Vanta
- Privacy program aligned with GDPR and UK GDPR
AI That Never Trains on Your Data
Haydn's AI features process your documents solely to provide the service to you. We never use your data — documents, financials, or personal information — to train AI models, and our AI service providers are bound to the same restriction.
Continuous Security Enhancements
Security is an ongoing commitment, not a one-time achievement. We continuously improve our security posture through rigorous processes and proactive planning.
Regular third-party penetration tests and continuous vulnerability scanning identify and remediate weaknesses before they become risks.
A documented incident response plan with defined roles, severity levels, and communication procedures — including breach notification in line with GDPR requirements.
Continuous database backups with point-in-time recovery, and documented business continuity and disaster recovery plans with defined recovery time and recovery point objectives.
Questions about our security?
If you have any questions or require further details about our security, privacy, or compliance measures, contact us at support@haydn.ai or get in touch below.