Skip to content

HAYEN PTE. LTD. / Trust & transparency

Security & Data

Public website: implemented controls

This site is delivered over HTTPS. Images and branding are local assets. The public demo runs with fictional data in the browser and is not connected to production WhatsApp, customer records or real booking systems.

Demo and contact forms send enquiries to a dedicated HAYEN endpoint. It validates requests, checks allowed origins, limits payloads and submission frequency, checks a bot-trap field and suppresses duplicates. Privileged database writes occur server-side; the website contains no service-role key and exposes no public lead reads or direct database writes.

Product controls

Hayen’s product work includes separation between business accounts, appointment workflows, delivery safeguards, customer memory, follow-up scheduling and human escalation. Hayen Command gives operators conversation context, appointment status and items needing attention.

Actions are designed around approved business information and rules. A clinical question should be routed to the clinic team, not answered as a diagnosis. A handover preserves useful context so a person can decide what happens next. This website illustrates those workflows; it is not an authenticated operator workspace.

Deployment-specific safeguards

Access roles, operator permissions, provider settings, audit records, retention periods and recovery arrangements must be verified for the particular customer deployment. They are not established by this public website. Backups, restoration testing and recovery objectives should be agreed before production customer data is introduced; no specific recovery guarantee is made here.

Data minimisation and provider review

Businesses should supply only the information needed for the service, set suitable follow-up preferences and limit who can access customer context. Customer-facing notices, consent requirements and cross-border processing need to be reviewed for the actual deployment.

Messaging, hosting and AI providers are dependencies, not automatic endorsements. Their access, security and data-handling terms must be checked before they are connected to customer operations.

Testing and assurance

Hayen’s development process includes model qualification, automated workflow QA and simulated customer conversations. We do not publish unverified test counts or claim that automated testing eliminates every risk.

No SOC 2, ISO 27001, government certification, external security audit or independent penetration-testing certification is claimed. Designed safeguards and internal tests are not the same as independent assurance.

Reporting a concern

Use the Security category on our Contact page for responsible security enquiries. Include a way to reach you and a concise description. Do not include passwords, access tokens or unnecessary personal data. The form does not accept file attachments.

Please do not test unrelated systems, disrupt availability or attempt to access customer data. A contact form does not authorise security testing or promise a reward or response time.