Fairhaven Data

Security overview

How we receive, hold, share, and delete the data entrusted to us. This page is written to be attached to a Data Management and Licensing Agreement.

Isolation

One environment per party
Each data owner and each buyer receives its own credentialed environment. A party can see only the files in its own environment. There are no shared drop folders.
Sharing by explicit grant
When data owned by one party must be delivered to another, we attach a read-only view of the specific folder to the receiving party. Nothing is copied by hand, and the grant can be revoked at any time.

Transport and storage

In transit
SFTP (SSH) for file transfer; TLS 1.2+ for the browser uploader and the client portal. Plain FTP is not offered.
At rest
Files are stored in encrypted object storage in the United States. The transfer server holds no long-term copy on its own disk.
Large files
Multi-gigabyte deliveries are supported with resumable transfer, so a dropped connection does not require starting over.

Access

Credentials
Each party receives unique SFTP credentials (password or SSH key). Credentials are issued and reset by Fairhaven Data staff, not by shared links.
Portal login
The client portal uses one-time codes sent to the registered email address. There is no portal password to reuse or leak.
Brute-force protection
Repeated failed logins are automatically blocked at the network edge.
Staff access
Administrative access is limited to named Fairhaven Data personnel with multi-factor authentication, on a need-to-know basis.

Logging and reporting

Audit trail
Every login, upload, download, and delete is recorded with the account, timestamp, and file. Logs are retained for the life of the agreement and made available on request.
Client reporting
The portal lists every file received from a party, its status, and the revenue attributed to it. These are the same figures we pay against.

Retention and deletion

During the agreement
Files remain in the party's environment for the retention period stated in the Data Order. Automatic expiry can be configured per folder.
On termination
The party's environment and its contents are deleted, and deletion is confirmed in writing, consistent with the Effect of Termination provisions of the agreement.

Suppression and consent

Suppression lists delivered by a data owner are honored across every downstream use. We require buyers to accept restrictions at least as strict as those in the originating Data Order, and we retain the consent records a data owner provides alongside its data.

Incidents

If we become aware of unauthorized access to a party's data, we notify the party's designated contact without undue delay, describe what was affected, and share the steps taken. Incident contact: security@fairhavendata.com.

Fairhaven Data is a service of Mavaos, LLC, a Massachusetts limited liability company. This overview describes our operating practices and is provided for information; the governing terms are those of the executed agreement and Data Order.