Back to Hytribe
Enterprise onboarding · Appendix
Security & Data Handling
What member data Hytribe receives, where it goes, who processes it, and how we protect it. Written for enterprise security and privacy review — with honest status on every control.
TLS in transit
LiveTenant isolation by community_id
LiveSOC 2 readiness
PlannedEncryption at rest (managed)
In reviewIncident notification 72h
LiveSigned DPA available
LiveSection 1
What data Hytribe receives
Hytribe only receives the member fields you choose to send. There is no tracking pixel, no background collection, and no access to your wider systems.
| Field | Category | Purpose |
|---|---|---|
| platform_user_id | Pseudonymous ID | Upsert key. Never resolved to real-world identity. |
| display_name | Personal data | Shown in tribe introductions. |
| interests, goals | Personal data | Primary matching signal; embedded into a vector. |
| engagement_tier, availability, timezone_offset_hours | Personal data | Secondary matching signals. |
| Onboarding answers | Personal data | Free-text answers used to enrich the profile. |
| Tribe message content | Personal data (optional) | Only where the Discord gateway or platform webhooks are enabled; processed for facilitation and health scoring. |
| Wellbeing / psychological assessment data | Not processed | Disabled at tenant level for enterprise tenants. |
No special-category data for enterprise tenants
Hytribe matches on behavioural and stated-preference signals only. Standardised wellbeing instruments (WHO-5, UCLA-3) and derived psychological profiling are not part of the enterprise product and are disabled at the tenant level. No GDPR Article 9 special category — and no equivalent sensitive category under US state law — is processed on your behalf.
Section 2
How data flows
- Ingest over TLS. Your backend calls
POST /membersover HTTPS, authenticated with a per-community API key in theX-API-Keyheader. - Store. The member record is written to Hytribe's PostgreSQL database (Neon), isolated by
community_id. - Enrich. Freeform profile text is sent to Anthropic's Claude API to extract structured interests and goals.
- Embed. The profile string is sent to OpenAI's embeddings API which returns a 1536-dimension vector. The vector is stored in PostgreSQL via pgvector.
- Match. Matching runs entirely inside Hytribe's own infrastructure on the stored vectors. No member data leaves the platform at this stage.
- Facilitate. Anton generates tribe introductions and nudges via the Claude API, delivered through your messaging platform or by email via Resend.
Model providers, disclosed
Profile text is sent to OpenAI (embeddings) and Anthropic (enrichment and facilitation). Under current terms, API inputs from either provider are not used to train their models by default and our accounts are not enrolled in any data-sharing programme.
Section 3
Sub-processors
Every third party that may process member data. We commit to 30 days' notice before adding or replacing a sub-processor.
| Sub-processor | Purpose | Data received | Region |
|---|---|---|---|
| Railway | Application hosting | All data in transit through the API | US |
| Neon | PostgreSQL database | All stored member data and vectors | US / EU (per tenant) |
| OpenAI | Profile embeddings | Profile text (name, interests, goals, region) | US |
| Anthropic | Enrichment & facilitation | Profile text, onboarding answers | US |
| Resend | Transactional email | Email address, message content | US |
| Slack / Discord / Telegram | Delivery channel | Platform user IDs, message content | Customer's own tenancy |
Section 4
Standard security questionnaire
How is the API authenticated?
Per-community API keys sent in the
X-API-Key header over TLS. A key is scoped to a single community and can only read or write that community's data. Keys are stored hashed at rest.Is tenant data isolated?
Yes — all member records are scoped by
community_id and every authenticated request is constrained to its own community. Isolation is enforced at the application layer, with row-level checks in every query path.Environments — do customers integrate against production?
No. Hytribe provides an isolated sandbox at
sandbox.hytribe.xyz. Environment-prefixed keys (ht_test_ / ht_live_) are rejected at authentication before database access. Outbound platform messages and email are suppressed in sandbox, so a test match run cannot deliver a message to a live member.Is data encrypted in transit and at rest?
All API traffic is HTTPS/TLS 1.2+. Data at rest is encrypted by our managed database and hosting providers (AES-256 class). Provider-side attestations available on request.
Backup and recovery?
Daily automated backups with point-in-time recovery inside the managed database provider's backup window. Restores are tested quarterly.
Do you offer an SLA?
Pilot customers run on best-effort availability. Enterprise contracts include a 99.5% monthly uptime target with credit remedies; a formal, measured SLA lands with SOC 2 readiness.
Retention and deletion?
Member data is retained while your community is active and deleted within 30 days of contract termination, or on erasure request. See the Retention & Deletion Policy for the full schedule.
Certifications — SOC 2, ISO 27001?
Not held today. SOC 2 Type I readiness is on the roadmap and we welcome vendor-security review under NDA. We will not imply a certification we do not hold.
Incident response?
Documented process with named on-call. We commit to notifying customers of a confirmed personal data breach without undue delay, and in any event within 72 hours of becoming aware.
Penetration testing?
Continuous automated dependency and secret scanning today. A third-party penetration test is scheduled ahead of the first enterprise production deployment.
Cyber liability insurance?
In arrangement. Coverage limits shared under NDA on request during procurement.
Vendor review
Request a tailored questionnaire response
Send us the framework and turnaround your security team needs. We return the completed pack — SIG-Lite, CAIQ, HECVAT or your own — with DPA and sub-processor list on request.
Enterprise sales
Ship your security review with a working pilot
We pair with your security team on questionnaire, DPA and SIG-Lite in parallel with a 30-day pilot on real member data.
30-day paid pilot Enterprise DPA ready
Need the signed pack for review?
We'll send the current Security & Data Handling Pack, DPA and sub-processor list under NDA.
Enterprise pilot · DPA + sandbox + solutions engineer
Book pilot call