Security
Last updated: 23 July 2026Hartia is built and operated by Dubir Group LTD(Cyprus). Your clients' personal data, the passports, addresses, and family details behind every document, is exactly the kind of data that has to stay protected. This page summarises how we secure the Service and how to report a vulnerability.
1. Encryption in transit
All traffic to Hartia is served over HTTPS (TLS). Requests over plain HTTP are redirected to HTTPS, and we send HTTP Strict Transport Security (HSTS) so browsers refuse to connect insecurely.
2. Authentication & passwords
Passwords are never stored in plain text; we keep only a salted hash, and no one at Dubir Group LTD can see your password. Sessions use bearer tokens, not cookies, so there is no cross-site session to hijack.
3. Access control & data isolation
Every firm's data is scoped to its own account. One firm cannot read or write another firm's clients, proposals, templates, or branding. Requests for data you do not own are rejected server-side, not just hidden in the interface.
4. Payments, we never touch your card
Subscription and top-up billing is handled by Creem.io, our merchant of record, on PCI-DSS-certified payment infrastructure. Card details are entered on Creem's hosted checkout, so full card numbers never reach or get stored on Hartia's servers. Webhooks we receive from Creem are verified by cryptographic signature before we act on them.
5. Client intake links
When your firm sends a client an intake form, the client opens it through an unguessable, high-entropy link, no account or password required for them. The link cannot be enumerated to reach another client's form or documents.
6. On-premise option
On the On-premise plan the entire application, database, and generated documents run on hardware physically located in your office. Client personal data never leaves your control and is never sent to our servers, which is the strongest isolation we can offer for firms that need it.
7. Infrastructure & backups
The Cloud plan runs on managed infrastructure in the European Union, with access restricted to authorised operators. We take regular backups so your data can be recovered, and we apply security updates to our dependencies on an ongoing basis.
8. Sub-processors
We share data only with the service providers needed to run Hartia, under contracts requiring appropriate safeguards:
- Cloud hosting (Fly.io, EU region): runs the application and stores the database on the Cloud plan.
- Creem.io: merchant of record; processes subscription and top-up payments and handles VAT.
- PostHog: product usage analytics.
- Self-hosted Umami: website and campaign analytics on our own infrastructure.
- Email delivery (Brevo): sends account emails and delivers documents on your behalf.
See the Privacy Policy for how personal data is handled and your rights under GDPR.
9. Your data is yours
You can export your workspace at any time and delete your account. We do not sell your data, and we do not use your clients' data or your documents to train AI models.
10. Breach notification
No system is perfectly secure. If a personal-data breach affecting you occurs, we will notify you and the relevant supervisory authority as required by GDPR and Cyprus data-protection law.
11. Reporting a vulnerability
We welcome responsible disclosure. If you believe you have found a security issue, email [email protected] with the details and steps to reproduce. Please give us a reasonable chance to investigate and fix the issue before disclosing it publicly, and avoid accessing or modifying data that is not yours. We are grateful for reports made in good faith and will acknowledge them.
12. Contact
Security questions or reports: [email protected].