Trust
Security
Last updated 26 July 2026
Hansala is built so confirmed evidence cannot be faked by a single party. Security practices follow that product rule.
Practices
- Authentication via Supabase Auth; sessions use HTTP-only cookies.
- Agent API keys are stored hashed (`hs_` prefix). Scopes limit what a key can do.
- Row-level security and operator checks scope data to the owning company.
- Confirmations (partners, references, case studies) require a human action — agents invite only.
- Transport is HTTPS in production. Secrets live in environment config.
Report a vulnerability
Email security@hansala.com with steps to reproduce. Please allow reasonable time before public disclosure. Do not access other customers’ data while testing.
Machine-readable disclosure: /.well-known/security.txt
More
Privacy · Status · Developers