This morning we intended to run the user acceptance test and start building role-specific kits. We did neither. Instead, through careful diagnostic work, we discovered a cross-tenant privilege escalation โ any user who had ever signed up could, in roughly three database writes, appoint themselves the leader of any other user on the platform and read and modify that person's compensation records inside their real employer's organization.
"We found a cross-tenant privilege escalation on a platform with zero external users. That is the cheapest possible moment to find one. A week later it would have been a breach notification."
The single most important sentence for this report
๐ด CRITICAL: Cross-Tenant Escalation
Closed at three layers
Any signed-up user could insert other users into their personal org without consent, assign themselves as their leader, and access compensation data (MBO, reviews, coaching notes, 1:1s, pay records). Closed with: membership injection block, leader-assignment validation, relationship validator requiring both parties in same org. Plus 28 policies binding relationship org to data org. Verified with repeatable exploit-chain test.
โ
Pilot Access Model Shipped
14-day trial retired
Single coherent limit: 60 analyses per user, no expiry. Notification at 50. Replaces four disagreeing enforcers (call_limit said 10, trial_state said 50, tier map said 10, client resolver synthesized a fourth). Disabled trial-expiration cron. Updated landing page, pricing page, onboarding, dashboards, banners, modals, and five email templates. Pilot users never see card prompts or paywall.
โ
Terms-of-Service Gate โ Now Real
Consent finally recorded
Gate existed but never worked. Accept button wrote to non-existent column, keyed on wrong field, wrapped in error catch. Zero of 52 acceptances recorded. Fixed: correct table, correct key, timestamp + version recorded, enforced server-side, verified by execution (403 without acceptance, 200 with). Enterprise data handling claim is now true.
โ
Invite Flow โ Fixed 100% Failure
Three bugs in one function
Selected non-existent column (p.sdr_email). Hardcoded role='sdr' (invited AEs labeled as SDRs). COALESCE never overwrote current_role (users landed on wrong dashboard). All three fixed, verified end-to-end with real authenticated sessions, data repair applied to affected rows.
โ
Self-Service Role Escalation โ Closed
Onboarding RPC validated
Any new user could call onboarding directly and set themselves to sdr_leader, ae_leader, or any leader value. Now validated against caller's available_roles (admin-gated). Also fixed: legitimate multi-role users who switched to leader role could never switch back โ guard was one-way door. Fixed.
โ ๏ธ Public Exposure Removed
Internal page taken offline
index2.html (team updates) was publicly reachable. Contained: named Adobe executives with candid assessments, pilot account counts for named prospect, attributed validation-call notes, count of unfixed security findings. Removed, confirmed 404. Never indexed but one URL guess away from exposure.
Also Fixed
Sitemap corrected (pointed at old domain, 3 paid-traffic landing pages missing). org_id backfill: trigger was writing personal workspace as org on analysis history (leader and team views returned nothing). Fixed trigger, repointed 35 rows. Owner and admin separated: dropped self_assessment_select policy that let org admins read private IC self-assessments (contradicted privacy principle).
This is the largest single advantage Hyvara has over every competitor in the space. We did not build another generic startup legal package. We built a coherent legal, governance, security, and commercial framework grounded in the Hyvara Constitution and reflecting what we actually are: a platform that amplifies human judgment rather than replacing it.
"Every document reflects the same constitutional principle: people are heroes, AI amplifies, the system is a producer, credibility includes 'I don't know,' and what we refuse to do matters as much as what we do."
Foundation as competitive advantage
The Hyvara Constitution
Complete working manuscript now compiled into a single coherent document. Prologue + 12 chapters spanning the founding vision, operating philosophy, organizational principles, and implementation framework. This is the north star for every legal document, every product decision, and every hire we make.
๐ข Core Commercial Agreements
1. Hyvara Terms and Conditions โ Foundation contract for all customer relationships. Establishes access, authorized users, Customer Content, Conversation Records, Private Brains, AI Outputs, recording and transcription, prohibited uses, customer stories, Expert Marketplace, Knowledge Federation, confidentiality, privacy, security, IP, fees, termination, disclaimers, indemnification, liability.
2. Hyvara Privacy Notice โ Personal data handling, collection purposes, disclosure rights, retention periods, individual rights. Distinguishes processor role (on customer data) from controller role (business operations).
3. Hyvara Data Processing Addendum (DPA) โ B2B privacy contract for enterprise customers processing personal data. Defines roles, processing instructions, confidentiality, security obligations, subprocessors, individual rights requests, privacy-impact assistance, incident notification, deletion, audits, international transfers, U.S. state privacy, model-provider restrictions, recording safeguards.
4. Hyvara Enterprise Order Form and SaaS Agreement โ Commercial contracting framework. Subscription terms, renewal, product packages, Hives, users, usage limits, fees, support, hosting, implementation responsibilities, security documents, data-processing terms, negotiated special terms. Includes implementation responsibility matrix.
๐ก๏ธ Security, AI Governance & Operations
5. Hyvara Acceptable Use Policy โ Permits: preparation, discovery, coaching, knowledge retrieval, sales collaboration, technical collaboration, implementation continuity, customer success, renewal, expansion, learning. Prohibits: deceptive recording, autonomous employment decisions, fabricated evidence, unsupported promises, misuse of customer stories, unauthorized confidential information, marketplace manipulation, security abuse, impersonation, harmful activity, surveillance, using AI as final authority for consequential decisions.
6. Hyvara AI Use and Governance Policy โ Producer-in-the-room model formalized. AI amplifies, doesn't replace human judgment, authority, accountability, or trust. Risk classification, governance, data limitation, model-provider review, knowledge provenance, freshness, testing, human review, forecasting safeguards, workplace safeguards, correction, appeals, monitoring, transparency, security, incident response. Includes AI System Review Record for elevated-risk features.
7. Hyvara Security Overview and Addendum โ Customer-facing enterprise security review. Governance, shared responsibility, data classification, identity and access, encryption, software security, infrastructure, logging, vulnerability management, model-provider security, live-meeting protection, Private Brain isolation, Knowledge Federation, backups, business continuity, incident response, vendors, personnel security, retention, customer assurance. Includes security-control verification checklist and customer security questionnaire.
8. Hyvara Recording and Meeting Consent Standard โ Pre-meeting notice, in-meeting notice, affirmative consent, participant objections, late joiners, external guests, shared rooms, live assistance, product recording states, buffering, raw media, transcripts, Conversation Records, workplace safeguards, sensitive meetings, access, retention, correction, legal preservation, international meetings. Includes host language templates and Meeting Processing Decision Record.
๐ Data, Knowledge & Marketplace
9. Hyvara Data Retention and Deletion Policy โ Schedule for raw audio/video, transcripts, meeting chat, Conversation Records, Private Brain knowledge, prompts, outputs, embeddings, indexes, caches, marketplace records, support records, security logs, billing, analytics, marketing, backups. Defines complete deletion workflows (transcripts, summaries, embeddings, indexes, caches, derived knowledge, subprocessors, backups). Includes legal-hold procedures, account-termination handling, system-by-system retention register, legal-hold record.
10. Hyvara Expert Marketplace Agreement โ Expert participation, identity and credential verification, ownership, customer licenses, confidential information, employer and customer IP rights, content quality, freshness, AI-assisted content, ratings, reviews, pricing, royalties, payouts, taxes, refunds, fraud, direct professional services, customer relationships, privacy, security, copyright complaints, takedowns, appeals, suspension, termination. Central principle: access through employment, consulting, or customer work does not grant commercialization rights.
11. Hyvara Copyright and Takedown Policy โ Copyright notices, counter-notifications, removal, restoration, repeat infringers, Private Brains, marketplace content, customer stories, software, documentation, AI-generated material, derived artifacts, evidence preservation. Includes notice and counter-notice forms, internal takedown-review record, implementation checklist. Requires DMCA registration before relying on safe-harbor protection.
๐ Transparency, Incidents & Vendor Management
12. Hyvara Subprocessor List and Vendor Transparency Schedule โ Publicly identifies vendors processing customer data or materially supporting services. Cloud hosting, language-model providers, transcription, vector databases, identity, email, support, analytics, monitoring, payments, CRM. For each: legal entity, service, purpose, data categories, processing location, transfer mechanism, retention, model-training configuration. Vendor review, customer notice, objection rights, model-provider transparency, meeting providers, access boundaries, international transfers, government requests, incidents, deletion, offboarding. Includes new-vendor review record and customer-facing change-notice template.
13. Hyvara Internal Incident Response Plan โ Security incident detection, escalation, response, communication, remediation, recovery, post-incident review. External disclosure procedures, customer notification, regulatory reporting. Roles, responsibilities, escalation paths, communication templates, documentation requirements.
This package is not publication-ready or signature-ready. Every document carries bracketed placeholders for business decisions, legal review, and operational verification. What it is: a coherent working draft reflecting actual Hyvara operating principles, not generic startup boilerplate. Ready for structured review by outside counsel, product, security, privacy, legal, and operational leadership.
๐ฅ DOWNLOAD PACKAGE
1. Hyvara_Constitution.epub (80 KB)
Professional eBook format. Read on iPad, Kindle, iPhone, Android. Offline-capable. Download and open in any eBook reader. Perfect for: mobile reading, commute, portable library.
2. Constitution_Download.html
Team landing page. Share this with your team first. Includes: reading guide by role (first-time readers, leadership, product/engineering), chapter summaries, context explanation, discussion prompts, direct download buttons. This is your entry point.
3. Hyvara_Constitution_Complete.html
Browser version with table of contents and anchor links. Responsive design, works on all devices. Shareable via URL. Alternative for those who prefer browser reading over EPUB.
How to Use This Distribution Package
โ For your team: Send Constitution_Download.html as the entry point. It explains why they're reading, guides them by role, and lets them choose their format (EPUB or HTML). Make it part of onboarding.
โ For partners/investors: Send Constitution_Complete.html or EPUB for serious readers. This is the document that shows you've thought through operating principles.
โ For discussion: Use Constitution_Download.html reading prompts to facilitate team conversations. "What principle changed how you think about your work?" Start with those questions.
Constitutional principles embedded: People are heroes, not obstacles. AI amplifies, doesn't replace. System behaves like a producer supporting the human. Credibility includes saying "I don't know." Organizational knowledge preserves provenance. Failures become governed knowledge. Promises survive handoffs. AI uncertainty is visible. Every interruption must earn attention.
-
โ
Signup can open to external users
This morning we could not, and we did not know it. The cross-tenant escalation would have exposed every early customer's compensation records to every other customer. That is a launch blocker. It is now closed at three layers with verification.
-
โ
Enterprise trust claims are now enforceable
Consent is recorded, versioned, and enforced server-side. This claim appears on our trust page and in every enterprise conversation. It was not true this morning. Auditable from database.
-
โ
Pilot model is coherent end-to-end
One number (60). One enforcer. One notification. Copy, enforcement, email templates, all align. Early users won't be told 60 and blocked at 10.
-
โ
Leader visibility actually works
Team views of rep analyses were silently returning nothing (wrong org written by trigger). That's the core product surface โ what we sell to leaders โ and it was broken. Now fixed.
-
โ
Named prospects are no longer exposed
index2.html removal. Reputational risk eliminated on relationships we cannot afford to lose.
-
โ
Legal and governance foundation is documented
13 working-draft documents cover what Hyvara is and what it refuses to be. Constitution is now reflected consistently across legal terms, privacy, AI governance, marketplace, security, and vendor management. Enterprise counsel can review coherent framework.
| # |
Issue |
Severity |
Status |
| 1 |
Terms gate never recorded consent, analysis ran anyway |
High |
Closed, verified by execution |
| 2 |
Any user could self-assign leader role via onboarding RPC |
High |
Closed, validated against available_roles |
| 3 |
Org admins could read private IC self-assessments |
Medium |
Policy dropped, principle restored |
| 4 |
Admin role conflated workspace ownership with people leadership |
High |
Separated (Phase A), 40+ checks repointed |
| 5 |
Internal page with named prospects publicly reachable |
High |
Removed, confirmed 404 |
| 6 |
Cross-tenant privilege escalation (compensation access) |
CRITICAL |
Closed at 3 layers, exploit-chain test verified |
-
Read-only diagnostics before every build
Every productive move started with a diagnostic, not a change. Stopped a 50-site refactor against a table that had never been dropped. Surfaced the escalation by asking "what would break if we changed this?" rather than guessing what might be wrong.
-
Verification by execution, not inspection
Invite fix, terms gate, and exploit chain all proven by running them with real authenticated sessions. Every claim verified that way held. Several claims verified by reading alone did not. Set the bar: "ran it, here's the response" beats "typecheck clean."
-
Lovable stopped instead of complying
Twice: when a prompt was built on a false premise, and when a proposed change would remove 30+ live read sites. Both times it reported the mismatch and waited. Saved more time than any fix.
-
Refusing to fabricate a pass
When authenticated tests couldn't execute, reported that rather than claiming success from inspection. A skipped test we know about beats a green check we can't trust.
-
Guardrails written into the system
Four traps documented in AGENTS.md (current_role SQL keyword collision, profiles.id vs user_id mismatch, relationship-based auth must constrain on org, team_id holds user id not FK). Build agent reads it every request. Doesn't depend on anyone remembering.
-
Constitutional principles drive implementation
13 legal and governance documents all reflect the same Hyvara Constitution. Human accountability is central, not an afterthought. AI amplifies, doesn't replace. What the system refuses to do is as important as what it does.
-
1. Trust the system, not the summary
Six separate premises arrived as confident summaries and turned out to be wrong: table reported dropped wasn't; bug diagnosed from historical rows, not current behavior; direct writes reported at line numbers that didn't exist; landing page input reported present that was removed; phantom role value that was a SQL keyword collision; policy reported as checking a relationship when only one variant did. Every one settled in minutes by reading the actual schema and executing the actual path. Going forward: summaries are hypotheses, not facts.
-
2. Done means verified, not declared
Several changes reported complete based on typecheck passing or function shape reading correctly. Typechecks don't catch queries against non-existent columns. Terms gate passed every inspection and had never once recorded an acceptance. Going forward: a report of "done" should name what proved it. "Typecheck clean" is not proof. "Ran it, here's the response" is.
-
3. Estimates without checking are just guesses
Entitlement fix scoped as "read-layer change" when the underlying table had 30+ read sites. Implication that owner/admin work created the cross-tenant exposure was wrong; the hole predated it by months. Both cases: assertions made without checking the system itself. Our entire lesson today was about that exact pattern.
-
4. Internal and public content must be separated
index2.html wasn't linked or sitemap'd but was one URL guess away from named prospects reading candid assessments. Process gap: internal and public share one deploy folder. Fix: separate them, don't rely on remembering.
-
5. UAT is still ahead of us
Everything today cleared the road to a walkthrough that nobody has walked. Work was necessary, sequencing was right, but the deliverable design is waiting on โ real list of what breaks from a user's seat โ does not exist. That's first thing tomorrow. Do not delay it again.
-
6. Documentation is debt or asset, not optional
Four traps documented in AGENTS.md, migration log carries the full chain, exploit-chain test is saved and repeatable. Or it all lives in someone's head and rediscovered by the next person. We chose asset. Keep choosing it.
Everything cleared today was preparation for a walkthrough that has not yet happened. The road is now open. The testing script does not exist. The test accounts are not set up. The file uploads have not been documented. The login flow has not been walked by a real user. Start tomorrow morning. This is the only thing that matters until it is done.
Product design team is waiting on this deliverable
-
๐จ UAT Execution Plan (Due Tomorrow)
Complete testing script covering: fresh signup โ email verification โ role selection (SDR, AE, Leader) โ pairing to another user โ running analysis on a sample call โ scheduling a 1:1 โ writing an MBO objective. Document logins, test accounts, files to upload, success criteria. This is the blueprint for the design team's walkthrough and the foundation for the full UAT plan.
-
๐ Full UAT Plan (Parallel Track)
Once execution plan is validated, expand to: multi-user scenarios (SDR team, AE handoff, Leader visibility), edge cases (role switches, org changes, data conflicts), performance validation, browser/device compatibility. Assign testing phases, define pass/fail criteria, schedule rollout.
-
๐ Test Environment Setup
Fresh Supabase branch or isolated org for UAT. Test accounts pre-seeded. Sample call recordings loaded. Org structure configured. Clean slate, repeatable from known state.
-
๐น UAT Documentation
Video walkthrough of successful path. Screenshot atlas of key screens. Copy all onboarding and UI text. Record actual responses from analyses. Use this to align design, product, and team on what "done" looks like.
3. Entitlement consolidation (Phase B)
Remove blanket org-wide grant from 18 policies where precise relationship check already exists. Currently any admin or manager reads every rep's MBO, coaching, 1:1s instead of only own reports. Blocked behind Phase C (separate admin from leadership role).
4. Role enforcement cleanup
Stop create_org_on_signup writing admin. Unblock enforce_roles function (currently fails on all four leadership relationships). Both depend on Phase C completion.
5. Doctrine map to product surfaces
Framework principles from Get to No Quickly mapped to product implementation. Frameworks currently in one head + manuscript; every kit is a translation. Create explicit mapping for team alignment.
6. team_id naming and FK integrity
Holds user id across 12 tables with no foreign key. Integrity issue, not security. Documented in AGENTS.md, not yet fixed.
-
Tomorrow morning: Run UAT
Fresh signup, role selection, AE pairing, analysis, 1:1, MBO objective. With real users. What breaks shows up in this session. This is the priority override โ everything else waits.
-
Parallel: Legal validation track
Place documents in version control. Create decision tracker. Product-reality review (compare statements to how platform works). Outside counsel review gates publication.
-
Role consolidation phases (B, C)
Phase B: narrow org-wide grants. Phase C: separate admin from leadership. Unblocks signup role cleanup and enforce_roles. Sequence matters โ don't start B until A proves stable.
-
Doctrine map to product
Make frameworks explicit and testable. Kit builders need to know what they're implementing.