Security
We take the security of your data seriously. Here is an overview of the practices and infrastructure that protect your content on Hiravi.
Authentication
User authentication is handled by Clerk, a dedicated identity platform. Passwords are never stored by Hiravi. We support sign-in via Google and other OAuth providers.
Data Storage
All files are stored in Amazon S3 with server-side encryption (SSE-S3). Database records are stored in Amazon Aurora DSQL with encryption at rest and in transit.
Transport Security
All connections to Hiravi use TLS 1.2 or higher. API endpoints and file uploads are served exclusively over HTTPS.
Access Control
Decks are private by default. Public visibility is opt-in per deck. Only authenticated owners can delete or modify their content. Server-side ownership checks are enforced on all mutations.
Reporting a Vulnerability
If you discover a security vulnerability in Hiravi, please report it responsibly via our GitHub repository. We will acknowledge your report within 72 hours and work to address confirmed issues promptly. We appreciate the efforts of security researchers who help keep our users safe.