๐Ÿ”’ Pre-UAT Hardening & Legal Framework Session

July 28, 2026 ยท Sunday
End of Day Report

Found and closed what would have
been a breach.

Discovered and closed a cross-tenant privilege escalation that would have let any signed-up user appoint themselves the leader of any other user and read and modify their compensation records inside their real employer's organization. Closed at three independent layers and verified with a repeatable exploit-chain test. Retired the 14-day trial model. Fixed a terms-of-service gate that never recorded consent. Fixed an invite flow broken 100% of the time. Removed an internal page from public view. Built a complete first-generation legal, governance, security, and commercial documentation package. Can now open signup to external users, which we could not do this morning.

The Honest Framing
We set out to run UAT. We found a breach instead.

This morning we intended to run the user acceptance test and start building role-specific kits. We did neither. Instead, through careful diagnostic work, we discovered a cross-tenant privilege escalation โ€” any user who had ever signed up could, in roughly three database writes, appoint themselves the leader of any other user on the platform and read and modify that person's compensation records inside their real employer's organization.

"We found a cross-tenant privilege escalation on a platform with zero external users. That is the cheapest possible moment to find one. A week later it would have been a breach notification."
The single most important sentence for this report
What Shipped Today (Product)
Six fixes before UAT could happen
๐Ÿ”ด CRITICAL: Cross-Tenant Escalation
Closed at three layers
Any signed-up user could insert other users into their personal org without consent, assign themselves as their leader, and access compensation data (MBO, reviews, coaching notes, 1:1s, pay records). Closed with: membership injection block, leader-assignment validation, relationship validator requiring both parties in same org. Plus 28 policies binding relationship org to data org. Verified with repeatable exploit-chain test.
โœ… Pilot Access Model Shipped
14-day trial retired
Single coherent limit: 60 analyses per user, no expiry. Notification at 50. Replaces four disagreeing enforcers (call_limit said 10, trial_state said 50, tier map said 10, client resolver synthesized a fourth). Disabled trial-expiration cron. Updated landing page, pricing page, onboarding, dashboards, banners, modals, and five email templates. Pilot users never see card prompts or paywall.
โœ… Terms-of-Service Gate โ€” Now Real
Consent finally recorded
Gate existed but never worked. Accept button wrote to non-existent column, keyed on wrong field, wrapped in error catch. Zero of 52 acceptances recorded. Fixed: correct table, correct key, timestamp + version recorded, enforced server-side, verified by execution (403 without acceptance, 200 with). Enterprise data handling claim is now true.
โœ… Invite Flow โ€” Fixed 100% Failure
Three bugs in one function
Selected non-existent column (p.sdr_email). Hardcoded role='sdr' (invited AEs labeled as SDRs). COALESCE never overwrote current_role (users landed on wrong dashboard). All three fixed, verified end-to-end with real authenticated sessions, data repair applied to affected rows.
โœ… Self-Service Role Escalation โ€” Closed
Onboarding RPC validated
Any new user could call onboarding directly and set themselves to sdr_leader, ae_leader, or any leader value. Now validated against caller's available_roles (admin-gated). Also fixed: legitimate multi-role users who switched to leader role could never switch back โ€” guard was one-way door. Fixed.
โš ๏ธ Public Exposure Removed
Internal page taken offline
index2.html (team updates) was publicly reachable. Contained: named Adobe executives with candid assessments, pilot account counts for named prospect, attributed validation-call notes, count of unfixed security findings. Removed, confirmed 404. Never indexed but one URL guess away from exposure.
Also Fixed
Sitemap corrected (pointed at old domain, 3 paid-traffic landing pages missing). org_id backfill: trigger was writing personal workspace as org on analysis history (leader and team views returned nothing). Fixed trigger, repointed 35 rows. Owner and admin separated: dropped self_assessment_select policy that let org admins read private IC self-assessments (contradicted privacy principle).
Legal & Governance + Constitutional Framework
Complete foundation delivered: 13 legal documents + Constitution

This is the largest single advantage Hyvara has over every competitor in the space. We did not build another generic startup legal package. We built a coherent legal, governance, security, and commercial framework grounded in the Hyvara Constitution and reflecting what we actually are: a platform that amplifies human judgment rather than replacing it.

"Every document reflects the same constitutional principle: people are heroes, AI amplifies, the system is a producer, credibility includes 'I don't know,' and what we refuse to do matters as much as what we do."
Foundation as competitive advantage
The Hyvara Constitution
Complete working manuscript now compiled into a single coherent document. Prologue + 12 chapters spanning the founding vision, operating philosophy, organizational principles, and implementation framework. This is the north star for every legal document, every product decision, and every hire we make.
โ†’ Hyvara_Constitution_Complete.html (Ready for counsel, investors, leadership)
Complete Legal & Governance Package
13 working-draft documents, all v0.1
๐Ÿข Core Commercial Agreements
1. Hyvara Terms and Conditions โ€” Foundation contract for all customer relationships. Establishes access, authorized users, Customer Content, Conversation Records, Private Brains, AI Outputs, recording and transcription, prohibited uses, customer stories, Expert Marketplace, Knowledge Federation, confidentiality, privacy, security, IP, fees, termination, disclaimers, indemnification, liability.
2. Hyvara Privacy Notice โ€” Personal data handling, collection purposes, disclosure rights, retention periods, individual rights. Distinguishes processor role (on customer data) from controller role (business operations).
3. Hyvara Data Processing Addendum (DPA) โ€” B2B privacy contract for enterprise customers processing personal data. Defines roles, processing instructions, confidentiality, security obligations, subprocessors, individual rights requests, privacy-impact assistance, incident notification, deletion, audits, international transfers, U.S. state privacy, model-provider restrictions, recording safeguards.
4. Hyvara Enterprise Order Form and SaaS Agreement โ€” Commercial contracting framework. Subscription terms, renewal, product packages, Hives, users, usage limits, fees, support, hosting, implementation responsibilities, security documents, data-processing terms, negotiated special terms. Includes implementation responsibility matrix.
๐Ÿ›ก๏ธ Security, AI Governance & Operations
5. Hyvara Acceptable Use Policy โ€” Permits: preparation, discovery, coaching, knowledge retrieval, sales collaboration, technical collaboration, implementation continuity, customer success, renewal, expansion, learning. Prohibits: deceptive recording, autonomous employment decisions, fabricated evidence, unsupported promises, misuse of customer stories, unauthorized confidential information, marketplace manipulation, security abuse, impersonation, harmful activity, surveillance, using AI as final authority for consequential decisions.
6. Hyvara AI Use and Governance Policy โ€” Producer-in-the-room model formalized. AI amplifies, doesn't replace human judgment, authority, accountability, or trust. Risk classification, governance, data limitation, model-provider review, knowledge provenance, freshness, testing, human review, forecasting safeguards, workplace safeguards, correction, appeals, monitoring, transparency, security, incident response. Includes AI System Review Record for elevated-risk features.
7. Hyvara Security Overview and Addendum โ€” Customer-facing enterprise security review. Governance, shared responsibility, data classification, identity and access, encryption, software security, infrastructure, logging, vulnerability management, model-provider security, live-meeting protection, Private Brain isolation, Knowledge Federation, backups, business continuity, incident response, vendors, personnel security, retention, customer assurance. Includes security-control verification checklist and customer security questionnaire.
8. Hyvara Recording and Meeting Consent Standard โ€” Pre-meeting notice, in-meeting notice, affirmative consent, participant objections, late joiners, external guests, shared rooms, live assistance, product recording states, buffering, raw media, transcripts, Conversation Records, workplace safeguards, sensitive meetings, access, retention, correction, legal preservation, international meetings. Includes host language templates and Meeting Processing Decision Record.
๐Ÿ“Š Data, Knowledge & Marketplace
9. Hyvara Data Retention and Deletion Policy โ€” Schedule for raw audio/video, transcripts, meeting chat, Conversation Records, Private Brain knowledge, prompts, outputs, embeddings, indexes, caches, marketplace records, support records, security logs, billing, analytics, marketing, backups. Defines complete deletion workflows (transcripts, summaries, embeddings, indexes, caches, derived knowledge, subprocessors, backups). Includes legal-hold procedures, account-termination handling, system-by-system retention register, legal-hold record.
10. Hyvara Expert Marketplace Agreement โ€” Expert participation, identity and credential verification, ownership, customer licenses, confidential information, employer and customer IP rights, content quality, freshness, AI-assisted content, ratings, reviews, pricing, royalties, payouts, taxes, refunds, fraud, direct professional services, customer relationships, privacy, security, copyright complaints, takedowns, appeals, suspension, termination. Central principle: access through employment, consulting, or customer work does not grant commercialization rights.
11. Hyvara Copyright and Takedown Policy โ€” Copyright notices, counter-notifications, removal, restoration, repeat infringers, Private Brains, marketplace content, customer stories, software, documentation, AI-generated material, derived artifacts, evidence preservation. Includes notice and counter-notice forms, internal takedown-review record, implementation checklist. Requires DMCA registration before relying on safe-harbor protection.
๐Ÿ“‹ Transparency, Incidents & Vendor Management
12. Hyvara Subprocessor List and Vendor Transparency Schedule โ€” Publicly identifies vendors processing customer data or materially supporting services. Cloud hosting, language-model providers, transcription, vector databases, identity, email, support, analytics, monitoring, payments, CRM. For each: legal entity, service, purpose, data categories, processing location, transfer mechanism, retention, model-training configuration. Vendor review, customer notice, objection rights, model-provider transparency, meeting providers, access boundaries, international transfers, government requests, incidents, deletion, offboarding. Includes new-vendor review record and customer-facing change-notice template.
13. Hyvara Internal Incident Response Plan โ€” Security incident detection, escalation, response, communication, remediation, recovery, post-incident review. External disclosure procedures, customer notification, regulatory reporting. Roles, responsibilities, escalation paths, communication templates, documentation requirements.
This package is not publication-ready or signature-ready. Every document carries bracketed placeholders for business decisions, legal review, and operational verification. What it is: a coherent working draft reflecting actual Hyvara operating principles, not generic startup boilerplate. Ready for structured review by outside counsel, product, security, privacy, legal, and operational leadership.
Distribution Ready
Constitution packaged for team โ€” 3 formats, ready to share
๐Ÿ“ฅ DOWNLOAD PACKAGE
1. Hyvara_Constitution.epub (80 KB)
Professional eBook format. Read on iPad, Kindle, iPhone, Android. Offline-capable. Download and open in any eBook reader. Perfect for: mobile reading, commute, portable library.
2. Constitution_Download.html
Team landing page. Share this with your team first. Includes: reading guide by role (first-time readers, leadership, product/engineering), chapter summaries, context explanation, discussion prompts, direct download buttons. This is your entry point.
3. Hyvara_Constitution_Complete.html
Browser version with table of contents and anchor links. Responsive design, works on all devices. Shareable via URL. Alternative for those who prefer browser reading over EPUB.
How to Use This Distribution Package
โ†’ For your team: Send Constitution_Download.html as the entry point. It explains why they're reading, guides them by role, and lets them choose their format (EPUB or HTML). Make it part of onboarding.
โ†’ For partners/investors: Send Constitution_Complete.html or EPUB for serious readers. This is the document that shows you've thought through operating principles.
โ†’ For discussion: Use Constitution_Download.html reading prompts to facilitate team conversations. "What principle changed how you think about your work?" Start with those questions.

Constitutional principles embedded: People are heroes, not obstacles. AI amplifies, doesn't replace. System behaves like a producer supporting the human. Credibility includes saying "I don't know." Organizational knowledge preserves provenance. Failures become governed knowledge. Promises survive handoffs. AI uncertainty is visible. Every interruption must earn attention.

Value to the Product & Company
This morning we couldn't ship. Tonight we can.
Security Finding Summary
Six issues found and closed in sequence
# Issue Severity Status
1 Terms gate never recorded consent, analysis ran anyway High Closed, verified by execution
2 Any user could self-assign leader role via onboarding RPC High Closed, validated against available_roles
3 Org admins could read private IC self-assessments Medium Policy dropped, principle restored
4 Admin role conflated workspace ownership with people leadership High Separated (Phase A), 40+ checks repointed
5 Internal page with named prospects publicly reachable High Removed, confirmed 404
6 Cross-tenant privilege escalation (compensation access) CRITICAL Closed at 3 layers, exploit-chain test verified
Done Wells (What Worked)
Repeatable practices from today
Do Betters (What We'll Improve)
Six lessons from confident wrong premises
Critical Next Phase โ€” Do Not Delay
User Acceptance Testing (UAT) is now the priority override
Everything cleared today was preparation for a walkthrough that has not yet happened. The road is now open. The testing script does not exist. The test accounts are not set up. The file uploads have not been documented. The login flow has not been walked by a real user. Start tomorrow morning. This is the only thing that matters until it is done.
Product design team is waiting on this deliverable
  • 3. Entitlement consolidation (Phase B)
    Remove blanket org-wide grant from 18 policies where precise relationship check already exists. Currently any admin or manager reads every rep's MBO, coaching, 1:1s instead of only own reports. Blocked behind Phase C (separate admin from leadership role).
  • 4. Role enforcement cleanup
    Stop create_org_on_signup writing admin. Unblock enforce_roles function (currently fails on all four leadership relationships). Both depend on Phase C completion.
  • 5. Doctrine map to product surfaces
    Framework principles from Get to No Quickly mapped to product implementation. Frameworks currently in one head + manuscript; every kit is a translation. Create explicit mapping for team alignment.
  • 6. team_id naming and FK integrity
    Holds user id across 12 tables with no foreign key. Integrity issue, not security. Documented in AGENTS.md, not yet fixed.
  • What's Coming Next
    Tomorrow and forward