Security
Trust has to be designed, not merely promised.
Heeded handles identity, personal reflection, life context, goals, commitments, group content, messages, community activity, and eventually payment data. The security posture has to match the sensitivity of those surfaces.
Data minimization
Collect only what is needed for account operation, personalization, security, product delivery, and the features a member intentionally uses.
Server-enforced permissions
Private surfaces should be protected by authenticated access and permission checks enforced on the server rather than trusted to the browser.
Secrets stay server-side
Infrastructure keys, service credentials, payment secrets, administrative access, and AI provider secrets should not be exposed in client code.
Least privilege
Services and staff should receive only the access required to perform their function.
Heeded does not claim SOC 2, ISO 27001, HIPAA, or any other certification that has not actually been completed.