Security & Trust

How we protect your project

This page is maintained by Our Haus to answer common security and privacy questions about the product. It is not a third-party audit or certification.

Encryption in transit

All traffic to Our Haus uses TLS. Project data, contracts, photos, and messages travel over encrypted connections between your device and our infrastructure.

Per-user data isolation

The database enforces row-level security so each user only sees data for projects, properties, and messages they're a member of. Server functions re-validate the caller on every request.

Modern authentication

Email + password, Google, and Apple sign-in are supported. Passwords are checked against the Have I Been Pwned breach database, and sessions use short-lived bearer tokens.

Payments handled by Stripe

Card details are entered directly into Stripe — Our Haus never sees or stores full card numbers. We only store transaction metadata and status.

Least-privilege access

Admin-level database keys are only used by trusted server-side code paths (webhooks, scheduled jobs). Day-to-day reads and writes go through scoped, per-user credentials.

Email deliverability & abuse controls

We send from an authenticated subdomain with SPF/DKIM. Public AI endpoints are rate-limited by IP, and contract-generation endpoints require proof of project ownership.

Shared responsibility

Our Haus provides the platform, the per-user access controls, encryption, and abuse mitigations described above. You're responsible for choosing a strong password, only inviting people who should see your project, and reviewing any AI-generated proposal or scope before signing or paying.

Contact

Privacy policy →Terms of service →Contact →← Back to home