Security overview
How we receive, hold, share, and delete the data entrusted to us. This page is written to be attached to a Data Management and Licensing Agreement.
Isolation
- One environment per party
- Each data owner and each buyer receives its own credentialed environment. A party can see only the files in its own environment. There are no shared drop folders.
- Sharing by explicit grant
- When data owned by one party must be delivered to another, we attach a read-only view of the specific folder to the receiving party. Nothing is copied by hand, and the grant can be revoked at any time.
Transport and storage
- In transit
- SFTP (SSH) for file transfer; TLS 1.2+ for the browser uploader and the client portal. Plain FTP is not offered.
- At rest
- Files are stored in encrypted object storage in the United States. The transfer server holds no long-term copy on its own disk.
- Large files
- Multi-gigabyte deliveries are supported with resumable transfer, so a dropped connection does not require starting over.
Access
- Credentials
- Each party receives unique SFTP credentials (password or SSH key). Credentials are issued and reset by Fairhaven Data staff, not by shared links.
- Portal login
- The client portal uses one-time codes sent to the registered email address. There is no portal password to reuse or leak.
- Brute-force protection
- Repeated failed logins are automatically blocked at the network edge.
- Staff access
- Administrative access is limited to named Fairhaven Data personnel with multi-factor authentication, on a need-to-know basis.
Logging and reporting
- Audit trail
- Every login, upload, download, and delete is recorded with the account, timestamp, and file. Logs are retained for the life of the agreement and made available on request.
- Client reporting
- The portal lists every file received from a party, its status, and the revenue attributed to it. These are the same figures we pay against.
Retention and deletion
- During the agreement
- Files remain in the party's environment for the retention period stated in the Data Order. Automatic expiry can be configured per folder.
- On termination
- The party's environment and its contents are deleted, and deletion is confirmed in writing, consistent with the Effect of Termination provisions of the agreement.
Suppression and consent
Suppression lists delivered by a data owner are honored across every downstream use. We require buyers to accept restrictions at least as strict as those in the originating Data Order, and we retain the consent records a data owner provides alongside its data.
Incidents
If we become aware of unauthorized access to a party's data, we notify the party's designated contact without undue delay, describe what was affected, and share the steps taken. Incident contact: security@fairhavendata.com.
Fairhaven Data is a service of Mavaos, LLC, a Massachusetts limited liability company. This overview describes our operating practices and is provided for information; the governing terms are those of the executed agreement and Data Order.