Trust center

How we protect the work you trust us with.

Community-serving organizations hold some of the most personal information there is. This page explains what’s true today, what Starhaven One is being built to do, and how to reach us about security.

01 / Where things stand

Clear about what’s real today.

Starhaven One is in development and does not hold any real client information. We won’t accept any until the requirements for that organization have been reviewed and met.

This website

When you contact us

  • Pages are served over encrypted HTTPS connections.
  • A strict content security policy lets pages run only our own code.
  • No advertising cookies or tracking pixels.
  • Inquiries go to our business inbox and are never entered into an AI tool.
  • Inquiry information is kept for 24 months, or deleted sooner if you ask.
Read the privacy notice →
Starhaven One

What the platform is being built to do

  • A separate workspace for every organization, tested specifically against one organization reaching another’s records.
  • Staff roles that control who can see and change what.
  • An audit log of administrative actions and changes to records.
  • Organization-wide data export in JSON and CSV.
  • Multi-factor sign-in required for Starhaven’s own administrator accounts.

These describe Starhaven One as it’s being built. It is not yet a finished or independently audited system.

02 / Responsible AI

AI for paperwork, never for decisions.

These rules apply to any AI feature in Starhaven One, and to how we handle what you send us today.

Automated decisions

Drafts, not decisions

AI will not decide eligibility, legal matters, benefits, or anything else with consequences for the people you serve.

Unreviewed output

A person approves

AI-generated content is reviewed by authorized staff before it becomes part of a record or is shared outside your organization.

Hidden providers

No surprises

Starhaven One doesn’t include AI features today. Before any are turned on for your organization, we’ll tell you exactly how they work and which providers are involved.

03 / Hard questions

Questions to ask any software vendor.

Ask them of us, too. Here are our honest answers.

Do you hold any of our clients’ information today?

No. Starhaven One is in development and holds no real client information. A pilot will start only after your organization’s privacy, confidentiality, reporting, and security requirements have been reviewed.

Do you have a SOC 2 report or other certifications?

Not yet. We’re an early-stage company and haven’t completed an independent audit. We’ll tell you exactly where we stand before any pilot begins, and we won’t claim a certification we don’t have.

Are our records kept separate from other organizations’?

Yes. Every organization gets its own workspace, and Starhaven One is tested specifically to confirm that one organization’s staff can’t reach another organization’s records.

Can we get our data out?

Yes. Starhaven One includes organization-wide data export in JSON and CSV, and program reports export as CSV and PDF.

What if our program handles regulated information?

Starhaven One is designed to work alongside, not replace, the regulated or specialized systems your programs may already require. If it isn’t the right place for a type of record, we’ll say so plainly.

04 / Security reports

Found a security issue? Tell us.

Email hello@starhaventech.com with “Security” in the subject line, and include enough detail for us to reproduce the problem.

  • We’ll acknowledge your report and keep you updated while we fix it.
  • Please don’t access, change, or delete data that isn’t yours, or disrupt the service.
  • Please give us a reasonable chance to fix the issue before sharing it publicly.

Our contact details are also published in machine-readable form at /.well-known/security.txt.