APIs and Integrations Policy
Rules for HABORA's APIs, webhooks, connectors and integrations with third-party systems, focused on security.
- Version
- 1.0
- Published on
- July 1, 2026
- Last updated
- July 1, 2026
- Next scheduled review
- July 1, 2027
1. Purpose
This Policy governs HABORA's APIs, webhooks, web services, connectors and integrations with third-party systems.
2. Integrations
HABORA may integrate with ERPs, CRMs, payment gateways, email, WhatsApp, AI, digital signature, storage, authentication, BI, financial systems and document APIs.
3. Authorization
Integrations must be authorized by a user with appropriate permission and linked to the company, module, scope and purpose.
4. Security
APIs must observe authentication, authorization, tokens, scopes, rate limits, logs, encryption in transit, segregation by company and revocation of credentials.
5. Keys and tokens
API keys, tokens and secrets must not be shared publicly, sent through insecure channels or stored in plain text.
6. Third parties
HABORA is not responsible for failures, charges, unavailability, changes or incidents of third parties outside its direct control.
7. Revocation
Integrations may be suspended due to security risk, abusive use, contractual breach, recurring failures, plan termination or a Customer request.
Contact
Questions, legal requests, privacy requests, formal communications and requests related to this policy should be sent to juridico@haborahub.com.br.
Updates
This policy may be revised to reflect legal, regulatory, technical, commercial or operational changes. The current version will remain available in the HABORA Compliance area. Material changes may require new acceptance by users, where applicable.