How Himaya protects your workspace, your data, and your customers, and the controls, certifications, and policies that back it up.
Here you can review our security controls and policies, request access to gated documents, and contact hello@himaya.ai with security or due-diligence questions.
Controls
Infrastructure security
Data encrypted at rest with AES-256
Data encrypted in transit with TLS 1.2+
Keys held in a dedicated KMS with scheduled rotation
Organizational security
SSO/SAML supported for every workspace
Multi-factor authentication enforced
Least-privilege access by default
Product security
Each customer runs in a logically isolated tenant
Agent memory, data, and models never cross tenant boundaries
Your content is never used to train shared models
Secure development
Static analysis and secret detection on every push
Merges blocked on critical or high severity findings
Secret scanning with push protection
FAQ
How is our data encrypted?
All data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Keys live in a dedicated KMS with scheduled rotation.
Where is our data processed?
Regional processing keeps data in your jurisdiction, across the US, EU, and GCC.
Is our content used to train models?
No. We process only what’s needed to secure your workspace. Your content is never used to train shared models.