Overview · April 21, 2026

Good afternoon, Tom.
Here's what needs your attention.

We scanned 6 connected sources and 1 device. We found 23 things worth fixing today, mostly old shared documents and forgotten credentials in your inbox.

Posture score
72/ 100
Up 8 pts this week

You're in better shape than 84% of Haven users — but a few things still need attention.

Your posture improved after you removed access from three former coworkers last Tuesday. The remaining critical issues are concentrated in your Gmail archive.

Sensitive items12,408
Critical issues3
High issues8
Exposed externally17 docs
Resolved this month47

Findings worth your attention

Source Severity
3 selected · 847 total findings
SSN visible in Gmail attachment shared with 4 external recipients Critical
Re: 2019 mortgage paperwork.pdf · 4 SSNs · 2 DOBs · Sent to: keith@oldcompany.com +3
GGmail
Financial PII
6 yrs old
Plaintext password in inbox — "Welcome to Acme Bank" Critical
Initial password sent in email body · Account still active · Never rotated
GGmail
Credential
8 mo old
Tax return shared via link with "anyone with the link can view" Critical
Tom_2023_Federal_Return.pdf · Public since Mar 2024 · 14 recent views
DDrive
Tax document
2 yrs old
Driver's license photo found in Photos library, backed up to iCloud High
IMG_2847.HEIC · Visible to anyone with iCloud Shared Albums access
iiCloud
Government ID
3 mo old
42 documents in shared folder with former coworker (last accessed 2021) High
"Q3 Planning – shared with Sarah K." · Contains: 3 contracts, 1 salary review
OOneDrive
Workplace data
5 yrs old
Medical records folder unencrypted in ~/Downloads High
7 PDFs · contains diagnostic codes, prescriptions · Indexed by Spotlight
MThis Mac
PHI
11 mo old
Credit card numbers in Stripe receipt emails (12 instances) Medium
Last 4 digits + expiry across 12 emails · Inbox not 2FA-protected via app
GGmail
Payment info
2+ yrs
"Notes.txt" on Desktop contains 8 saved API keys Low
OpenAI, AWS, GitHub tokens · Local only · not synced
MThis Mac
Credential
4 mo old
Haven Agent · Beta

Let Haven quietly clean up the easy stuff while you go about your day.

Haven Agent can revoke stale shares, move sensitive files to your encrypted vault, and delete obvious junk — all locally, with a one-click undo on every action.

Connected sources

Your data is scanned locally on this device. Nothing is uploaded.

G
Gmail
tom@example.com · 142,847 messages indexed
Active
D
Google Drive
12,409 files · 47 GB scanned
Active
O
OneDrive
3,847 files · token expires in 6 days
Re-auth soon
i
iCloud Photos & Drive
28,194 photos · 4,109 docs
Active
D
Dropbox
1,847 files · last scan 12 min ago
Active
M
This Mac (MacBook Pro)
Home folder · 218 GB indexed
Active

Recent activity

Your remediation history. Everything is reversible for 30 days.

Revoked external sharing on 14 Drive documents shared with former coworker
Today · 11:42 AM · undo available
Moved 23 sensitive PDFs from Downloads to encrypted Vault
Today · 9:18 AM
New critical finding: tax return now publicly viewable via shared link
Yesterday · 6:04 PM
Permanently deleted 147 expired emails containing 2FA codes and login links
Sun · 8:33 PM
Full re-scan completed across 6 sources · 12,408 sensitive items found
Apr 19 · 2:14 AM