Security

What Hela does so integrations do not open the door.

Secrets

  • Connection credentials (keys, tokens, certificates) are encrypted AES-256-GCM before being written, with a versioned INTEGRATIONS_KEY: a key rotation requires no manual re-encryption, the old one stays readable during the switch.
  • They are never returned by the API nor shown on screen; a set field reads Set.
  • API keys are stored only as their SHA-256 digest; webhook secrets, encrypted like credentials.
  • Connection logs are scrubbed: a recognisable token (Bearer …, sk_live_…, whsec_…, hela_live_…, a long opaque string) appearing in a partner's answer is replaced with ••• before being written.

API keys

  • Scopes: an explicit subset of permissions; permissions touching the account's people and money are forbidden to keys.
  • Test mode: read-only, by construction.
  • Rate limit per key, and 429 beyond.
  • Immediate revocation.
  • Every key request is logged in the company's audit with the key's prefix (request_events).

Outgoing webhooks

  • HTTPS required; private, local and link-local addresses refused at creation and on every delivery (DNS resolution checked: a name pointing to 10.0.0.1 is refused); redirects not followed; 15-second timeout.
  • Timestamped HMAC-SHA256 signature on every delivery; five-minute validity window.
  • No body beyond what the event carries: never a secret, never another customer's data.

Incoming webhooks

  • One address per connection, not guessable (/integrations/inbound/<provider>/<connection id>).
  • The partner's signature is verified when it provides one (Stripe, Mollie, Wave, Flutterwave, Yousign, DocuSign, M-Pesa, MTN…); otherwise the event is read back from the partner before being believed. A notification matching nothing is logged and ignored.
  • The raw body is kept for verification, never interpreted first.

OAuth

  • Authorization code flow with PKCE and a signed, single-use state bound to the company and the user who clicked; ten minutes' validity.
  • Minimal scopes: drive.file (one folder), Files.ReadWrite.AppFolder, and never full access to a Drive or a mailbox.
  • Refresh tokens are encrypted like the rest; reconnection is requested when the partner revokes them.

Company isolation

Every company has its database schema; connections, keys, webhooks and jobs carry the company id and are filtered by it in every query. One company's API key cannot name another company in a path: 404.

Fiscal regimes

  • Certificates and private keys (VFD, EFRIS) are encrypted like other credentials; signatures are computed server-side and the key never leaves the database.
  • The sealed journal makes any later change visible, which protects the company as much as the administration.

Reporting

A vulnerability is reported to security@hela.co. We acknowledge within 48 hours and publish a fix before publishing the detail.

Something wrong or missing? Write to us.