Invite-only access
There is no public account registration. An H2 administrator creates each client account and assigns it only to approved projects. New clients receive a time-limited setup link and choose a password that H2 never sees. Clients should use a unique password, ideally stored in a password manager.
Project separation
Access decisions are made on the server for every protected request. Client records, comments and design files are queried against the signed-in account and assigned project, so changing a link or request identifier does not grant access to another client’s work.
Safer design review
Review files are limited to validated static image formats, decoded and re-encoded on upload, and stored outside the public website directory. They are streamed only after an access check. Client comments are stored as plain text, size-limited and attached to a specific design version.
Admin controls and records
Administration requires a separate H2 administrator capability. Account creation, workspace creation, design publication and feedback changes are recorded in an activity trail. Protected pages and files use private, no-store caching rules and restrictive browser security headers.
Your part
Keep your account protected, use a password manager and sign out on shared devices. Never place passwords, API keys, payment information or other secrets in project comments. Tell H2 promptly if a team member should no longer have access.
Report a concern
If you believe you have found a security issue, email hello@h2.nz with a clear description. Please do not access other people’s data, disrupt the service or publish sensitive details while we investigate.
Last updated 25 August 2026