Haven is a calm, collaborative workspace where your team works with notes, files, apps, and data - encrypted by default and installable on any device. It runs on MindooDB, an open-source, local-first sync database you can run on your own servers, in your own jurisdiction; the server only ever sees ciphertext. Real data sovereignty, without giving up real-time collaboration.
Client-side keys, no plaintext on the server. Apps only see what you explicitly share. Fine-grained access control governs who can create, change or delete documents - enforced cryptographically, even offline.
Automerge-based merges, shared tenants, and a guided onboarding flow for bringing teams in.
Runs as a PWA on iOS, Android, and desktop. Add multiple instances for work, personal, and demos.
Full local use with built-in backup and flexible push-only, pull-only, or bidirectional sync.
Build apps with the MindooDB App SDK or have an AI generate them from the published context files.
When buyer, seller, and counsel work on the same confidential deal, each side keeps its own tenant. Haven brings the shared documents, Q&A, and closing tasks into one workspace - while the server only ever sees ciphertext, and every change becomes a signed node in a tamper-evident DAG.
Two AI hosts · ~23 min · generated by NotebookLM
A relaxed deep-dive into how Haven turns MindooDB into a browser-based workspace: end-to-end encrypted data with keys that never leave your device, local replicas for fast offline work, CRDT-based merging with a tamper-evident change history, strictly separated multi-tenant workspaces, custom apps, and virtual views that combine data across contexts. An entertaining and accessible introduction to the platform.
Pages, Chicklets, and groups let you arrange databases, applications, notes, web content, and media exactly the way your team thinks. Haven becomes the calm home screen for your encrypted data.
Haven is not a concept mockup. It is a working product that already brings together navigation, workspace organization, search, database access, and local-first workflows in the browser.
Click the workspace screenshot to inspect a much taller Haven page with notes, media, running apps, mind maps, Kanban boards, and Mermaid tiles in one real workspace.
Applications can run embedded in the Haven grid or in their own tab, access selected databases and views, and ship as either externally hosted web apps or Haven-hosted bundles served offline by the service worker.
Haven inherits MindooDB's trust model. Data is encrypted on the client before it ever leaves the device, apps run in sandboxed iframes with granular permissions, and the DAG explorer makes collaboration auditable.
Haven Community works in three topologies. Choose the one that matches your workflow - you can move between them without changing clients.
Create tenants and databases entirely offline. No server, no sync - ideal for personal use, drafts, and offline demos.
Push a local tenant to the hosted demo server and invite real collaborators. Demo data is wiped periodically - it is for evaluation, not production.
Point Haven at a MindooDB server you run. See README-server.md for setup.
The Haven PWA at haven.mindoodb.com. Free to use today, full local use, optional demo server, and self-hosting against your own MindooDB server.
Custom branding, managed UI and workspaces, in-house app store, workspace roaming, automatic backup, inline attachment editing, and more - from Mindoo GmbH.
Product updates and implementation notes from the MindooDB ecosystem.
25.08.2026
Haven now unlocks with a passkey: Face ID, Touch ID, or whatever else your device uses to recognise you. After your next password sign-in, Haven offers to set one up, and once it works you can remove the password entirely and never type one again. New user ids are created with the passkey option preselected. Administrator ids are the deliberate exception, because an admin account that only opens with this laptop's fingerprint is an admin account you lose with the laptop. And in Haven Enterprise, your workspace itself can now travel: tabs, tiles and your installed apps sync between your devices, encrypted with your user key, with as many separately named layouts as you like - one for phones, one for wide screens.
22.08.2026
We started wondering what the smallest machine is that can run a MindooDB server. The server only relays encrypted data - it never decrypts anything - so the requirements are mostly a Node.js runtime and some disk. While waiting for a box of mini PCs to arrive, I tried the least sensible option I had to hand: a Debian VM under emulated x86_64, inside UTM SE, on an iPhone 17. The Docker build took an hour and a quarter, generating the server identity took 102 seconds. And then it ran.
21.08.2026
MindooDB and Haven now give every person a user key that travels with them across every device they approve. Encrypting for a small circle was always possible - mint a key and pass it around by hand, which you can never take back, or have an administrator set up a distribution policy - but now it is simply a recipient list on the document. Take someone off that list and the document key rotates: they lose access on the next sync, attachments included. Key distribution addresses people instead of devices, so a new laptop no longer means rewriting who may read what.