H2.nz
Client sign inBook a website chat

Security at H2

Private work deserves more than a padlock icon.

The H2 workspace is designed around verified accounts, limited access and careful handling of client feedback and design files.

Invite-only access

There is no public account registration. An H2 administrator creates each client account and assigns it only to approved projects. New clients receive a time-limited setup link and choose a password that H2 never sees. Clients should use a unique password, ideally stored in a password manager.

Project separation

Access decisions are made on the server for every protected request. Client records, comments and design files are queried against the signed-in account and assigned project, so changing a link or request identifier does not grant access to another client’s work.

Safer design review

Review files are limited to validated static image formats, decoded and re-encoded on upload, and stored outside the public website directory. They are streamed only after an access check. Client comments are stored as plain text, size-limited and attached to a specific design version.

Admin controls and records

Administration requires a separate H2 administrator capability. Account creation, workspace creation, design publication and feedback changes are recorded in an activity trail. Protected pages and files use private, no-store caching rules and restrictive browser security headers.

Your part

Keep your account protected, use a password manager and sign out on shared devices. Never place passwords, API keys, payment information or other secrets in project comments. Tell H2 promptly if a team member should no longer have access.

Report a concern

If you believe you have found a security issue, email hello@h2.nz with a clear description. Please do not access other people’s data, disrupt the service or publish sensitive details while we investigate.

Last updated 25 August 2026