Security is a release gate.
Private beta: HiveWorth is under active security hardening. This page explains the intended security direction without claiming certifications or independent assurance that have not yet been completed.
Identity and authentication
The product is being designed around strong password controls, MFA support, short-lived sessions and guarded account recovery. Sensitive account changes should require recent authentication or equivalent verification.
Financial data access
Users should only be able to access records they are explicitly entitled to view. Household and business records are designed around ownership, membership and visibility rules.
Infrastructure direction
The long-term architecture is being designed so clients communicate with a controlled API rather than receiving direct database credentials. Administrative access should follow least-privilege principles.
Recovery
Password recovery is being designed around email possession plus an additional recovery factor. Recovery questions are treated as a secondary secret rather than a replacement for MFA or control of the account email.
Logging
Operational and security logs should avoid passwords, recovery answers, raw access tokens and unnecessary financial content.
Before public launch
- Automated cross-user and cross-household authorisation tests.
- Independent penetration testing.
- Dependency and secret scanning.
- Backup and restore exercises.
- Incident-response and key-rotation procedures.
- Full GDPR export and deletion workflows.