Security is a standing requirement across every Hamia product, not an added feature. This page explains our approach at a company level; for exactly what data we collect and why, see our Privacy Policy.
Hamia is built to keep every business's data separate from every other business's, and to give businesses control over who on their own team can reach it. That isolation is enforced at the platform level, not left to individual product teams to remember, and it applies the same way whether a business is on Hamia Agent, Studio, Manager, or API.
Full detail on what we collect, how we use it, how long we keep it, and your rights over it lives in our Privacy Policy, kept as the single source of truth for data handling rather than repeated here.
We encrypt stored platform access tokens, hash API keys rather than storing them in plain text, and enforce role based access controls so only authorised people can reach a given business's data. Access to Hamia's own internal tools requires staff authentication with multi factor verification.
Hamia runs on enterprise-grade cloud infrastructure, with encryption in transit and at rest, and a global content delivery and security layer protecting every product from common web attacks. We do not publish the exact vendors behind this infrastructure, the same reasoning we apply on our Products page: naming a specific stack publishes it to competitors for no real benefit to a business using Hamia.
Hamia staff access to business or customer data is limited to what a given role genuinely needs to do its job, gated behind authenticated, role based internal tools, not general database access. Staff accounts with elevated access require multi factor authentication on top of a verified sign in, not a password alone.
We design Hamia to align with applicable data protection laws in the regions we operate, including the GDPR for users in the EU and the CCPA for users in California. We do not currently hold formal third party security certifications, and we will update this page if that changes rather than claiming compliance we have not verified.
If you believe you have found a security vulnerability in a Hamia product, please report it to security@hamia.io rather than disclosing it publicly. We take every report seriously and will respond as quickly as we can.
For any other security or compliance question, contact us at hello@hamia.io.