Menu
SECURITY & DATA HANDLING / REVIEWED SEPTEMBER 21, 2026

Security boundaries you can evaluate before you buy.

HowAI Suite handles citation evidence, governance records and brand-accuracy work. This page states the controls present today—and the enterprise controls that are not yet available.

Inspectable evidenceProvider provenanceLimits kept visible
Current assurance boundary

HowAI Suite is not SOC 2 certified and does not currently offer SSO, SCIM, customer-managed encryption keys or a standard contractual uptime SLA. Request a scoped review before placing regulated or highly sensitive data in the service.

Transport and application controls

IN TRANSIT

HTTPS for public traffic

Production pages and API routes are served over HTTPS. Security headers include HSTS, frame blocking, MIME sniffing protection, a content security policy and a restrictive permissions policy.

IDENTITY

Protected credentials and sessions

Passwords are salted and hashed. Session and recovery tokens are stored as hashes; browser session cookies are Secure, HttpOnly and SameSite=Lax. Email password reset and MFA are not available today.

TENANCY

Organization-scoped access

Workspace records and product handoffs are queried within the authenticated organization. Role-aware workflows separate contribution, review and administration where the product supports them.

Storage, retention and deletion

Application data is stored in the production database and restricted server-side evidence storage. HowAICite does not currently provide application-layer field encryption or customer-managed keys. Daily operational backups remain on the same server and are retained for up to 14 days; off-site disaster recovery is not currently advertised.

Reports can be deleted in the workspace, and organization owners or admins can export organization data. Deleted records may remain in retained backups for up to 14 days. Billing records may be kept when required for tax, fraud prevention or legal compliance. See the privacy notice for the full data-use boundary.

AI-provider boundary

Automated observations use provider APIs. They are not automated recordings of the consumer ChatGPT, Claude, Gemini, Google AI Mode, Google AI Overviews or Copilot interfaces. A requested run may send the saved question and requested market or language context to the selected provider. Manual consumer-surface evidence remains user-supplied and is labeled separately.

Service providers

ProviderPurposeData boundary
Production infrastructure providerApplication hosting, server storage and operational backupsWorkspace, account and evidence data required to provide the service
PaddleMerchant of record, checkout, tax and subscription administrationBilling contact, order and subscription data; HowAICite does not receive full card details
OpenAIProvider-API answer observation when an OpenAI run is requestedSaved question and requested market/language context
AnthropicProvider-API answer observation when a Claude run is requestedSaved question and requested market/language context
GoogleGemini model-answer observation when a Gemini run is requestedSaved question and requested answer language; current connector has no web grounding
PerplexityProvider-API web-search observation when a Perplexity run is requestedSaved question and requested market/language context

The exact infrastructure vendor and regional hosting details are supplied during an enterprise review rather than inferred on this page. Provider availability and models may change; current operational status is shown in the coverage matrix.

Payments and secrets

Paddle hosts checkout and the customer portal as merchant of record. HowAICite does not receive or store full card numbers or card security codes. AI-provider credentials remain server-side and are not included in browser output, evidence exports or public pages.

Vulnerability disclosure

Report a suspected vulnerability to howaicite@gmail.com. Include the affected URL, impact and safe reproduction steps. Do not include passwords, API keys, recovery codes, payment-card data or confidential customer evidence, and do not access data that is not yours.

For procurement questions, review enterprise readiness or request a written security scope before onboarding.

START WITH A REAL BASELINE

Find the first gap worth fixing.

Inspect your website now, then add observed AI answers when you are ready to measure visibility.