Trust Center

Enterprise security.
Standard on every plan.

Haiku is a WalkMe product. SOC 2 Type II, ISO 27001, and ISO 27701 certified. The same security standards that protect 1 in 3 Fortune 500 companies now protect every guide you create.

Built to the standard your security team requires.

Certifications and compliance frameworks that protect your data at every level.

SOC 2 Type II

An independent auditor tested our security controls over time. Covers security, availability, and privacy.

Every tier

ISO 27001

The international standard for information security management. Security built into how we operate, not bolted on afterward.

Certified

ISO 27701

Privacy information management. Extends ISO 27001 to cover personal data handling, GDPR alignment, and privacy controls.

Certified

GDPR

EU General Data Protection Regulation. Full data subject rights: access, correction, deletion, portability. EU/UK/Swiss-US Data Privacy Framework registered.

Every tier

CCPA

California Consumer Privacy Act. Opt out of data sale, request deletion, and access your data at any time. Haiku operates as a CCPA Business.

Every tier

HIPAA

Business Associate Agreements available for healthcare organizations handling protected health information.

Enterprise

Encrypted at every layer.

Everything you capture with Haiku is encrypted in transit and at rest. Our infrastructure runs on Amazon Web Services.

Encryption

AES-256 at rest. TLS 1.2+ in transit. Industry-standard cryptographic implementation at every layer.

Cloud Infrastructure

Built on Amazon Web Services. WalkMe is an AWS Advanced Technology Partner with enterprise-scale infrastructure.

Data Residency

Haiku product data is stored in the European Union. Your workflows and guides remain within EU infrastructure.

AI & Your Data

How Haiku handles AI and your data.

Haiku uses AI to generate step descriptions, titles, and summaries from your captured workflows. Here is how we protect your data in the process.

Your content is not used to train AI models.

Haiku does not send your workflow data to third-party AI systems.

AI processing follows the same encryption and access controls as all other data.

Full details are documented in our Privacy Policy.

You Control Your Data.

Real controls over your data. Not just checkboxes.

  • Request deletion of your account and all associated data at any time.
  • Export your guides and data in standard formats.
  • Cookie consent managed through OneTrust. Review or update your preferences at any time.

Transparency note: We use analytics and marketing tools to improve Haiku and reach new users. This is described in our Privacy Policy. You can manage your preferences through our cookie consent tool at any time.

Your Data Rights
Access your data Available
Delete your account Available
Export your guides Available
Correct your data Available

Governance for teams that need it.

Haiku is a WalkMe product. When you use Haiku, you operate within that security boundary. Enterprise controls are available on Team and Enterprise plans.

Role-Based Access

Admin, Creator, and Viewer roles. Control who creates, edits, and views guides across your organization.

Audit Logs

Full activity history. Track who created, edited, shared, or deleted guides and when.

Single Sign-On

SAML-based SSO. Connect Haiku to your identity provider for centralized access management.

DPA Available

Data Processing Addendum for GDPR compliance. Available upon request for enterprise agreements.

Security Review Support

Dedicated questionnaire support for your procurement and security review process.

WalkMe Heritage

15 years of trust with the world's largest companies.

Haiku's security posture is inherited from WalkMe. The same systems that protect Fortune 500 workflows now protect every guide you create.

2011
Founded
35M+
Enterprise users
1 in 3
Fortune 500
42
Countries

Questions about security or privacy?

Reach out to our security and privacy teams directly.

Privacy & Data Requests

privacy@gethaiku.ai
For enterprise agreements, security questionnaires, and DPA requests.