05 · Trust Center · Updated February 8, 2026 · Version 1.1

Ruhavyn Vendor Security Questionnaire

Pre-Filled SIG-Style Security Assessment. Pre-filled answers to standard security assessment questions, so enterprise security teams can expedite vendor reviews.

Document
Vendor Security Questionnaire
Version
1.1
Last Updated
February 8, 2026
Owner
Ruhavyn Security Team
Classification
Public

How to Use This Document

This questionnaire provides pre-filled answers to standard security assessment questions based on the SIG (Standardized Information Gathering) framework. Enterprise security teams can use this document to expedite vendor security reviews.

For questions not covered here, contact: info@healingsunhaven.com

Section 1: Company Information

QuestionAnswer
Legal company nameHealing Sun Haven LLC
Trade name / DBARuhavyn
Headquarters locationUnited States
Year founded2024
Primary security contactinfo@healingsunhaven.com
Company websitehttps://ruhavyn.com
Service descriptionEnterprise wellness platform with AI therapy, meditation, mood tracking, and video content

Section 2: Application Security

2.1 Authentication & Access Control

#QuestionAnswer
2.1.1How are user passwords stored?Hashed using bcrypt via enterprise-grade authentication infrastructure. Never stored in plaintext.
2.1.2Do you support Single Sign-On (SSO)?Yes. SAML 2.0 and OIDC. Included in Complete Care, and available as a paid add-on for Essential Care and Advanced Care.
2.1.3Do you support Multi-Factor Authentication?Yes, via SSO provider integration. Native MFA via authentication service.
2.1.4How are sessions managed?JWT tokens with configurable expiration. Tokens validated on every request.
2.1.5What access control model do you use?Role-Based Access Control (RBAC): Admin, Member, Service roles.
2.1.6How is admin access restricted?Company-scoped isolation. Admins can only access their organization's data.
2.1.7Can admins access user passwords?No. Passwords are hashed and inaccessible to any administrator.
2.1.8Can admins read user diary entries?No. Diary entries are protected by RLS, so only the user can access them.

2.2 Data Protection

#QuestionAnswer
2.2.1What encryption is used for data at rest?AES-256 via enterprise-grade cloud infrastructure.
2.2.2What encryption is used for data in transit?TLS 1.3 for all connections.
2.2.3Are backups encrypted?Yes. AES-256 encryption on all backups.
2.2.4How are API keys stored?Hashed with SHA-256. Plaintext never stored. Only key prefix visible.
2.2.5How do you isolate customer data?Row Level Security (RLS) on all 37 database tables with company_id filtering.
2.2.6Is there cross-tenant data access possible?No. RLS policies cryptographically isolate all company data.
2.2.7Do you encrypt user email addresses?Yes. Military-grade AES-256 field-level encryption on all user emails (101/101 protected).

2.3 Application Security Controls

#QuestionAnswer
2.3.1How do you prevent SQL injection?Parameterized queries via secure database SDK. All 48 database functions hardened with SET search_path = public.
2.3.2How do you prevent XSS attacks?React's built-in escaping. Input sanitization on all user content.
2.3.3How do you prevent CSRF attacks?JWT-based auth with SameSite cookie policies.
2.3.4Do you have input validation?Yes. Client and server-side validation using Zod schemas.
2.3.5How many RLS policies are implemented?80 Row Level Security policies across all tables.
2.3.6How many database functions are secured?48 functions with hardened search_path settings.

Section 3: Infrastructure Security

3.1 Hosting & Architecture

#QuestionAnswer
3.1.1Where is the application hosted?Enterprise-grade cloud infrastructure (backend and frontend).
3.1.2Where is data stored geographically?United States (primary). EU hosting available upon request.
3.1.3What cloud provider is used?SOC 2 Type II and ISO 27001 certified cloud infrastructure.
3.1.4Is this a multi-tenant architecture?Yes, with strict data isolation via RLS.
3.1.5Where is SSO infrastructure hosted?Self-hosted on SOC 2 Type II certified infrastructure.

3.2 Network Security

#QuestionAnswer
3.2.1Is a WAF deployed?Yes, via enterprise cloud infrastructure.
3.2.2Is DDoS protection in place?Yes, via enterprise cloud infrastructure with automatic mitigation.
3.2.3Are all connections encrypted?Yes. TLS 1.3 required for all connections. HTTPS only.
3.2.4Is there network segmentation?Yes. Database, API, and frontend are isolated.

3.3 Business Continuity

#QuestionAnswer
3.3.1What is your uptime SLA?99.9% uptime SLA. Current performance: 99.95%.
3.3.2What is your Recovery Time Objective (RTO)?4 hours.
3.3.3What is your Recovery Point Objective (RPO)?1 hour.
3.3.4How often are backups performed?Daily automated backups with 7-day Point-in-Time Recovery.
3.3.5Do you have a disaster recovery plan?Yes. Documented DR plan with regular testing.
3.3.6Do you have a business continuity plan?Yes. Multi-region failover capability.

3.4 Physical Security

#QuestionAnswer
3.4.1Where are physical servers located?N/A. Cloud-native architecture with no on-premises infrastructure.
3.4.2What physical security controls are in place?Physical security managed by SOC 2 Type II certified cloud providers. Refer to infrastructure provider SOC 2 reports for physical security controls.
3.4.3Do employees have physical access to data?No. All data access is through authenticated, audited API connections.

Section 4: Compliance & Certifications

#QuestionAnswer
4.1Are you SOC 2 certified?SOC 2-ready infrastructure via certified providers (SOC 2 Type II). Formal Ruhavyn certification planned Q2 2026.
4.2Are you ISO 27001 certified?Aligned practices via ISO 27001 certified infrastructure.
4.3Are you GDPR compliant?Yes. Full GDPR compliance with data export, deletion, and EU hosting options.
4.4Are you CCPA compliant?Yes. Privacy controls and data rights implemented.
4.5Are you HIPAA compliant?HIPAA-ready infrastructure. BAA available upon request.
4.6Are you PCI DSS compliant?Via PCI DSS Level 1 certified payment processor. No card data stored in Ruhavyn systems.
4.7Do you have a DPA available?Yes. GDPR-compliant Data Processing Addendum available.
4.8Can you complete custom security questionnaires?Yes. Contact info@healingsunhaven.com.

Section 5: Data Management

5.1 Data Collection & Storage

#QuestionAnswer
5.1.1What personal data do you collect?Email, display name, mood entries, diary entries (optional), usage analytics.
5.1.2Do you collect sensitive health data?Mood self-reports and wellness reflections. No medical records or diagnoses.
5.1.3Do you collect payment information?No. Payment processed entirely by PCI DSS Level 1 certified payment provider.
5.1.4How long is data retained?User data: duration of account + 30 days. Audit logs: 90 days.
5.1.5Can users export their data?Yes. Full data export in JSON format via Settings.
5.1.6Can users delete their data?Yes. Account deletion with complete data purge within 30 days.

5.2 Data Sharing

#QuestionAnswer
5.2.1Do you sell personal data?No. Never.
5.2.2Do you share data with third parties?Only with carefully vetted sub-processors necessary for service provision (database infrastructure, payment processing, AI services). All sub-processors maintain SOC 2 Type II certification.
5.2.3Can employers see employee diary entries?No. Diary entries are protected by RLS, so only the user can access them.
5.2.4What analytics do employers see?Anonymized, aggregated data only. Minimum 10 users for any metric.

Section 6: Access Control

#QuestionAnswer
6.1What roles are available?Admin (company-scoped), Member (standard user), Service (API access).
6.2How are admin privileges restricted?Admins only see their company's data via RLS policies. Cannot access other companies.
6.3Is there privileged access management?Yes. Admin actions logged with IP, timestamp, and metadata.
6.4How is user provisioning handled?Manual via admin dashboard, bulk CSV import, or SCIM (Complete Care).
6.5How is user deprovisioning handled?Admin disables user → immediate access revocation → sessions invalidated.
6.6Is there separation of duties?Yes. Admin and Member roles with different permissions, enforced at database level.

Section 7: Monitoring & Logging

#QuestionAnswer
7.1Do you maintain audit logs?Yes. Comprehensive audit logging of all admin and security events.
7.2How long are logs retained?90 days (configurable for enterprise).
7.3Are logs tamper-proof?Yes. Append-only storage with integrity protection.
7.4Can customers export audit logs?Yes. CSV and JSON export (Advanced Care/Complete Care tiers).
7.5Do you have real-time monitoring?Yes. Automated monitoring with alerts for security events.
7.6What events are logged?Auth events, admin actions, API calls, failed logins, data access patterns.
7.7Is there intrusion detection?Yes. Anomaly detection on auth patterns and API usage.

Section 8: Incident Response

#QuestionAnswer
8.1Do you have an incident response plan?Yes. Documented 6-step process: Detection → Triage → Containment → Resolution → Notification → Post-mortem.
8.2What is your incident response time?Critical: 4-hour containment. Standard: 24-hour response.
8.3How do you notify customers of breaches?Without undue delay and within 2–3 business days of becoming aware of a breach.
8.4Have you experienced a data breach?No. Ruhavyn has not experienced any data breaches.
8.5Do you perform penetration testing?Internal security reviews completed. Third-party pentest planned Q2 2026.
8.6Do you have a bug bounty program?Planned Q3 2026 post-launch.

Section 9: Vendor Management

9.1 Sub-Processor Overview

We work with carefully selected service providers who meet our rigorous security and compliance standards. All infrastructure and service providers must:

  • Maintain SOC 2 Type II certification
  • Comply with ISO 27001 standards
  • Support GDPR and CCPA compliance
  • Provide HIPAA-ready infrastructure where applicable
  • Sign Data Processing Agreements with strict confidentiality terms

Categories of Sub-Processors:

Service CategoryPurposeSecurity Standards
Database & AuthenticationSecure data storage, user authentication, RLS policiesSOC 2 Type II, ISO 27001, HIPAA-ready
Payment ProcessingSubscription billing, payment securityPCI DSS Level 1, SOC 2 Type II
AI InfrastructureTherapeutic AI features, natural language processingSOC 2 Type II, enterprise-grade privacy
Frontend HostingWeb application delivery, CDNSOC 2 Type II, enterprise SLA
Enterprise SSOSingle Sign-On for corporate clientsSelf-hosted, SOC 2 certified infrastructure

9.2 Vendor Security

#QuestionAnswer
9.2.1How do you assess vendor security?Security questionnaire, SOC 2 reports, contractual requirements.
9.2.2Are all vendors SOC 2 certified?Yes. All primary vendors maintain SOC 2 Type II.
9.2.3How is data shared with AI providers?Non-sensitive data only (preferred names, general queries). No PHI/PII.
9.2.4Is user data used to train AI models?No. Contractually prohibited with all AI providers.
9.2.5How are vendor changes communicated?30-day notice for sub-processor changes per DPA.

For a complete list of sub-processors with detailed vendor information, compliance certifications, and data processing agreements, enterprise clients may contact: info@healingsunhaven.com

Section 10: API & Integration Security

#QuestionAnswer
10.1Do you provide API access?Yes. REST API available (Advanced Care/Complete Care tiers).
10.2How are API keys secured?SHA-256 hashed. Only prefix visible. Revocable anytime.
10.3Is there API rate limiting?Yes. Tier-based: 1,000/month (Advanced Care), 10,000/month (Complete Care).
10.4Do you support webhooks?Yes. HTTPS-only with HMAC-SHA256 signatures.
10.5Is there API documentation?Yes. OpenAPI specification available to customers.
10.6How are API keys rotated?Self-service rotation via admin dashboard. Recommended quarterly.

Section 11: Privacy & Data Rights

#QuestionAnswer
11.1Is there a privacy policy?Yes. Full details are available in the Trust Center at https://www.healingsunhaven.com
11.2Is there a DPA available?Yes. GDPR-compliant DPA available for download.
11.3Where is data processed?United States (primary). EU hosting available.
11.4How are international transfers handled?Standard Contractual Clauses (SCCs) for EU transfers.
11.5Can data residency requirements be met?Yes. EU hosting available as add-on.
11.6Do you support data subject requests?Yes. Export, deletion, and rectification supported.

Section 12: Additional Security Measures

#QuestionAnswer
12.1Do you have security training for employees?Yes. Annual security awareness training required.
12.2Do you perform background checks?Yes, for all employees with access to customer data or systems.
12.3Is there a secure development lifecycle?Yes. Security review required for all code changes.
12.4Do you use static code analysis?Yes. Automated scanning in CI/CD pipeline.
12.5How often are security reviews conducted?Quarterly internal reviews. Annual third-party assessment (planned).

Section 13: Insurance & SDLC

13.1 Insurance Coverage

#QuestionAnswer
13.1.1Do you carry cyber liability insurance?Yes. Cyber liability insurance is maintained to cover data breach and incident costs.
13.1.2Do you carry Errors & Omissions (E&O)?Yes. E&O insurance is maintained as part of our commercial insurance program.
13.1.3Can you provide proof of insurance?Yes, upon request for enterprise contracts. Contact info@healingsunhaven.com.

13.2 Software Development Lifecycle

#QuestionAnswer
13.2.1What is your code review process?All code changes require peer review before merging. Security-sensitive changes require additional security team review.
13.2.2What is your deployment pipeline?Git-based version control → automated CI/CD → staging environment → production deployment with rollback capability.
13.2.3How are secrets managed in development?Secrets stored in environment variables and secure vault. Never committed to source code.
13.2.4Do you perform dependency vulnerability scanning?Yes. Automated dependency scanning for known vulnerabilities in CI/CD pipeline.

Document References

For additional information, please see our complete Trust Center documentation:

DocumentDescription
SOC 2 Readiness ReportDetailed compliance documentation with 5-layer security architecture
Security SummaryOne-page executive overview
Security FAQCommon B2B security questions
Privacy & Security PolicyComprehensive data protection policy
Data Processing AddendumGDPR DPA template
Accessibility StatementWCAG 2.1 AA compliance
Admin FAQAdministrator documentation
User FAQEnd-user documentation

Questions?

General Inquiries: info@healingsunhaven.com

Support Team: support@healingsunhaven.com

Document Version: 1.1 | Last Updated: February 8, 2026

© 2026 Healing Sun Haven LLC. All rights reserved.