Security & Trust

Built to be private. Audited to stay that way.

Hapo Ndani's security posture is a combination of platform-inherited certifications, architectural guarantees, and open-source runtime choices you can verify yourself.

The core guarantee: Your files, your prompts, and your model work never leave your Mac. Apple handles the Mac App Store purchase and install path. Hapo Ndani does not see your files, your AI conversations, or your model output.

Inherited infrastructure certifications

Hapo Ndani runs on certified platforms. These certs are held by the platform — Hapo Ndani inherits the control framework.

GC
Google Cloud Run — SOC 2 Type II
Hapo Ndani's license backend runs on Cloud Run. Google's SOC 2 Type II audit covers availability, confidentiality, and security controls for the compute layer.
Platform: Google Cloud · Inherited
GC
Google Cloud — ISO 27001 / 27017 / 27018
Information security management (27001), cloud-specific security controls (27017), and cloud privacy protection (27018). All three apply to the GCP infrastructure Hapo Ndani runs on.
Platform: Google Cloud · Inherited
AS
Mac App Store purchase processing
App purchase and installation are handled by Apple. Hapo Ndani does not receive, store, or process card numbers, CVVs, or billing addresses.
Platform: Apple · Hapo Ndani is payment-data scope-reduced
NF
Netlify — SOC 2 Type II & ISO 27001
The nibiashara.biz website, including all Hapo Ndani pages and the download, is served from Netlify's certified CDN infrastructure.
Platform: Netlify · Inherited

Architectural security — verifiable from the code

Open-source runtimes & standards compliance

Privacy framework alignment (self-attested)

Planned security improvements (not yet complete)

Found a security issue?
Email admin@nibiashara.biz with subject "Hapo Ndani security report". We read every report and respond within 48 hours. No bug bounty program yet — but we'll credit you by name on this page if you prefer.