How we operate
Security, compliance, and the published document set. Geometry of a house that can be inspected.
HSH Intelligence is built on enterprise-grade security and operational transparency. This page exists so a buyer, legal team, or compliance officer can review how we handle data before a purchase.
Last updated: 15 April 2026
- Scope
- Professional capacity
- In transit
- TLS 1.3
- At rest
- AES-256
- DSAR
- 5 business days
The document set
Every published paper for a vendor review. Schema also lives in Docs for engineers, the copy is identical.
Data Processing Agreement
Controller roles and subprocessors.
Service Level Agreement
API uptime target 99%.
Acceptable Use Policy
How buyers may use the data.
Mutual NDA
Before a scoped conversation.
Terms
The commercial terms of sale.
Privacy
This site, cookies, and products.
Data schema
Fields, coverage, delivery formats.
Purpose
HSH Intelligence exists to be the most trusted house of B2B intelligence on the market. Premium data and ethical practices are not opposites. They are the same thing. Every decision about how we process and license data is guided by one test. Would we be comfortable if every regulator, buyer, and individual in a dataset could see exactly what we are doing. The answer is always yes.
Data quality standards
Every record goes through a multi-stage validation pipeline before it reaches a buyer. Emails are verified. Company profiles are cross-checked. Duplicate entries are eliminated. Incomplete or low-quality records are excluded from paid tiers.
We maintain internal quality and confidence scores for every record and continuously re-enrich datasets as new public information becomes available. When we say verified, we mean verified.
Security infrastructure
Infrastructure runs on enterprise-class cloud architecture with strict access controls at every layer. All data is transmitted over TLS 1.3. Storage is protected with AES-256 encryption. Access to raw datasets is governed by role-based permissions and fully logged for audit.
We do not store any buyer payment information on our servers. Card transactions are processed through PCI-compliant payment infrastructure. Systems are continuously monitored for unauthorized access, anomalous behavior, and potential vulnerabilities.
No public site is unhackable. This is the OWASP ASVS 5.0 browser baseline we ship on every response. We do not ship deprecated pins (HPKP), Expect-CT, or a cosmetic “firewall” widget.
Content Security Policy
Scripts, styles, frames, and connections are allow-listed. Inline event handlers are banned. Base-tag hijacks are banned. Violations report to this origin.
HSTS (HTTPS only)
After one clean HTTPS visit, the browser refuses HTTP for two years, including subdomains. Not preloaded, that lock is permanent and we will not flip it from here.
MIME sniffing off
A file cannot quietly become a script. Content-Type is law.
Clickjacking
Framing is limited to this origin and the Grok preview host. Random domains cannot overlay a fake checkout.
Permissions policy
Camera, mic, location, USB, HID, serial, Bluetooth, topics, and payment APIs are denied in this document.
Window isolation
Cross-origin opener isolation with popups allowed for Stripe and sign-in. Origin-keyed agent cluster on.
Method lock
TRACE and TRACK are refused. The only POST this origin accepts is the CSP violation sink, no cookies, no body stored.
Report a vulnerability: info@healingsunhaven.com. Researchers use the standard path /.well-known/security.txt, a plain-text file, not a page.
What we do not collect
HSH Intelligence does not sell sensitive personal data, private individual information, health records, financial personal data, or any data relating to individuals acting in a personal rather than professional capacity. Every record relates strictly to business entities and professionals operating in their professional capacity.
We do not include data on minors under any circumstances. We do not include private social profiles, personal email addresses, or material that sits behind an access wall.
Compliance
HSH Intelligence operates in compliance with applicable data-protection regulations including GDPR, CCPA, CAN-SPAM, and CASL. We maintain internal compliance documentation, data-processing records, and vendor security assessments.
Enterprise buyers requiring a Data Processing Agreement can read the full DPA at /dpa. The Acceptable Use Policy that governs how buyers may use our data is at /aup.
Your rights
If you are an individual whose professional information appears in our datasets and you wish to request removal, correction, or access, contact us at any time. We honor data-subject rights requests promptly and without friction. Email info@healingsunhaven.com. We respond within 5 business days.
Contact us
Healing Sun Haven LLC
Data division: HSH Intelligence
15442 Ventura Blvd, Suite 201-1914 Sherman Oaks, CA 91403
Email: info@healingsunhaven.com
Accessibility
This site targets WCAG 2.1 AA. Semantic HTML, one h1 per page, visible keyboard focus, skip link, and prefers-reduced-motion respected. Report gaps to info@healingsunhaven.com.
