Honua
// security & DPA

Know what Honua secures—and what remains yours.

Last updated: August 9, 2026

Honua Server is customer-managed by default. Honua secures the software and publishes deployment guidance; you control the cloud account, network, data, and runtime configuration unless a signed agreement assigns a responsibility differently.

Evaluating Honua's security posture? The Trust Center summarizes architecture, encryption, access control, data residency, attestation status, and the re-runnable public evidence behind each claim. This page covers the responsibility split and data-processing terms.

Security contact

Use security@honua.io for vulnerability reports, security questions, and responsible disclosure coordination. Share enough detail to reproduce the issue — affected version, deployment shape, impact, and clear reproduction steps where possible.

Shared responsibility · customer-managed by default

Shared security responsibility for a customer-managed Honua deployment
AreaDefault posture
Honua softwareHonua provides the application, images, SDKs, security fixes, and deployment guidance for the supported scope.
Cloud account & network controlsYou configure TLS, WAF rules, allowlists, backups, access to the cloud account, and infrastructure availability unless a signed agreement says otherwise.
Admin authenticationScoped API key by default. Public source implements single-provider OIDC under the Pro entitlement and multi-provider OIDC with custom claim-to-role mapping under Enterprise. OIDC remains off until configured; validate it as source-evaluation functionality before production.
Observability & hardeningHonua provides hardening guidance and reference configurations; your deploying team applies and monitors them.

Data Processing Addendum

DPA availability depends on the engagement model:

Website security and evaluation

Product & supply-chain security

These controls apply to Honua's software-development and release process; they do not replace the controls required in your deployment:

Offline and restricted-network deployments

Honua is self-hosted in your environment. Paid entitlements are validated locally without a connectivity-dependent license service, and the quickstart runs with no license key, no signup, and no phone-home. Network egress requirements beyond your own storage, database, and telemetry endpoints are therefore limited; validate the exact egress profile for your deployment shape during evaluation. A formally documented air-gapped installation path is not published yet.

Standards & self-attestations

Honua's developing control program uses the CSA Cloud Controls Matrix v4 to organize evidence that can also support future SOC 2, ISO 27001, and NIST CSF work. The table below states current status; it is not a certification claim.

Standards & self-attestations table
FrameworkStatus
CSA STAR Level 1 (CAIQ self-assessment)In progress
OWASP ASVS (application security)Level 1 self-attested; Level 2 gaps tracked
NIST CSF / CIS Controls v8 alignmentIn progress
SOC 2 Type IIPlanned

Request the compliance pack: the Trust Center enumerates which self-attestation artifacts are shareable on request today — the OWASP ASVS Level 1 self-assessment, answered SIG Lite questionnaire, CCM v4 control register walk-through, and the approved policy set — and which arrive later (the CAIQ after submission; the NIST CSF and CIS gap assessments once finalized). All are self-attested; none is a third-party certification. See Request the compliance pack or email security@honua.io.