HeapFileAI

Security review

Review HeapFile's current security and data boundaries.

HeapFile AI is live with local-first defaults and gated Premium services. Enterprise compliance certification has not been established; review the current capabilities and requirements before organization use.

Architecture boundary

  • Desktop local memory and local evidence stay on device unless a cloud feature is configured.
  • Account, membership, billing, support, and optional cloud services are separate from local-only data.
  • Release artifacts remain private and should be distributed through the account or approved support path.

Access and authorization

  • Users must authorize connector access through their own provider accounts or organization-approved flows.
  • HeapFile-owned GitHub, AWS, Microsoft, Atlassian, and other connectors should report not configured until the relevant authorization path exists.
  • Premium cloud endpoints must enforce entitlement server-side before being treated as delivered features.

Data handling

  • HeapFile does not need passwords, API keys, tokens, or raw customer data in support email.
  • Local exports and diagnostics should be minimized and redacted before sharing.
  • Retention, export, and deletion controls are documented on the data controls page.

Compliance status

  • Do not claim SOC 2, ISO 27001, HIPAA, GDPR adequacy, FedRAMP, or similar certification unless completed and approved in writing.
  • Independent security review, dependency audit, signed release distribution, incident-response testing, and enterprise legal review remain required before broad distribution or organization rollout.
  • Organizations can request a deeper review packet through support.

Review packet requests

Email admin@heapfile.com with the organization name, intended usage scope, operating systems, desired connectors, retention/export requirements, and any required questionnaire. Do not attach confidential production data or credentials.