05 · Trust Center · Updated February 8, 2026 · Version 1.1
Ruhavyn Vendor Security Questionnaire
Pre-Filled SIG-Style Security Assessment. Pre-filled answers to standard security assessment questions, so enterprise security teams can expedite vendor reviews.
Document
Vendor Security Questionnaire
Version
1.1
Last Updated
February 8, 2026
Owner
Ruhavyn Security Team
Classification
Public
How to Use This Document
This questionnaire provides pre-filled answers to standard security assessment questions based on the SIG (Standardized Information Gathering) framework. Enterprise security teams can use this document to expedite vendor security reviews.
User data: duration of account + 30 days. Audit logs: 90 days.
5.1.5
Can users export their data?
Yes. Full data export in JSON format via Settings.
5.1.6
Can users delete their data?
Yes. Account deletion with complete data purge within 30 days.
5.2 Data Sharing
#
Question
Answer
5.2.1
Do you sell personal data?
No. Never.
5.2.2
Do you share data with third parties?
Only with carefully vetted sub-processors necessary for service provision (database infrastructure, payment processing, AI services). All sub-processors maintain SOC 2 Type II certification.
5.2.3
Can employers see employee diary entries?
No. Diary entries are protected by RLS, so only the user can access them.
5.2.4
What analytics do employers see?
Anonymized, aggregated data only. Minimum 10 users for any metric.
Section 6: Access Control
#
Question
Answer
6.1
What roles are available?
Admin (company-scoped), Member (standard user), Service (API access).
6.2
How are admin privileges restricted?
Admins only see their company's data via RLS policies. Cannot access other companies.
6.3
Is there privileged access management?
Yes. Admin actions logged with IP, timestamp, and metadata.
6.4
How is user provisioning handled?
Manual via admin dashboard, bulk CSV import, or SCIM (Complete Care).
6.5
How is user deprovisioning handled?
Admin disables user → immediate access revocation → sessions invalidated.
6.6
Is there separation of duties?
Yes. Admin and Member roles with different permissions, enforced at database level.
Section 7: Monitoring & Logging
#
Question
Answer
7.1
Do you maintain audit logs?
Yes. Comprehensive audit logging of all admin and security events.
7.2
How long are logs retained?
90 days (configurable for enterprise).
7.3
Are logs tamper-proof?
Yes. Append-only storage with integrity protection.
7.4
Can customers export audit logs?
Yes. CSV and JSON export (Advanced Care/Complete Care tiers).
7.5
Do you have real-time monitoring?
Yes. Automated monitoring with alerts for security events.
7.6
What events are logged?
Auth events, admin actions, API calls, failed logins, data access patterns.
7.7
Is there intrusion detection?
Yes. Anomaly detection on auth patterns and API usage.
We work with carefully selected service providers who meet our rigorous security and compliance standards. All infrastructure and service providers must:
Maintain SOC 2 Type II certification
Comply with ISO 27001 standards
Support GDPR and CCPA compliance
Provide HIPAA-ready infrastructure where applicable
Sign Data Processing Agreements with strict confidentiality terms
Categories of Sub-Processors:
Service Category
Purpose
Security Standards
Database & Authentication
Secure data storage, user authentication, RLS policies
SOC 2 Type II, ISO 27001, HIPAA-ready
Payment Processing
Subscription billing, payment security
PCI DSS Level 1, SOC 2 Type II
AI Infrastructure
Therapeutic AI features, natural language processing
Non-sensitive data only (preferred names, general queries). No PHI/PII.
9.2.4
Is user data used to train AI models?
No. Contractually prohibited with all AI providers.
9.2.5
How are vendor changes communicated?
30-day notice for sub-processor changes per DPA.
For a complete list of sub-processors with detailed vendor information, compliance certifications, and data processing agreements, enterprise clients may contact: info@healingsunhaven.com
Section 10: API & Integration Security
#
Question
Answer
10.1
Do you provide API access?
Yes. REST API available (Advanced Care/Complete Care tiers).
10.2
How are API keys secured?
SHA-256 hashed. Only prefix visible. Revocable anytime.