Haven free beta Data sovereignty

Work together - online, offline, and across organizations.

Haven is a calm, collaborative workspace for notes, files, apps, and data - end-to-end encrypted, on every device, with the complete history of every change.

Missing an app?
Describe it, and the built-in App Builder writes it, publishes it, and installs it for you - no coding required. It all runs on MindooDB, an open-source, local-first sync database you can host in your own jurisdiction; the server only ever sees ciphertext - real data sovereignty, without giving up real-time collaboration.

Why Haven

Five things that set Haven apart

Secure by default
End-to-end encrypted

Client-side keys, no plaintext on the server. Apps only see what you explicitly share. Fine-grained access control governs who can create, change or delete documents - enforced cryptographically, even offline.

Collaborative
Multi-user by design

Automerge-based merges, shared tenants, and a guided onboarding flow for bringing teams in.

Cross-platform
Installable everywhere

Runs as a PWA on iOS, Android, and desktop. Add multiple instances for work, personal, and demos.

Local-first
Works without network

Full local use with built-in backup and flexible push-only, pull-only, or bidirectional sync.

Extensible
Real app platform

Describe the app your team is missing and the App Builder writes, hosts, and installs it - no coding required. Or build it yourself with the MindooDB App SDK.

In practice

From three orgs into one private workspace

When buyer, seller, and counsel work on the same confidential deal, each side keeps its own tenant. Haven brings the shared documents, Q&A, and closing tasks into one workspace - while the server only ever sees ciphertext, and every change becomes a signed node in a tamper-evident DAG.

Diagram showing three corporate parties - Buyer, Seller, and Law Firm - whose data flows through a single arrow into a central Haven workspace tile with a gold lock icon, illustrating cross-tenant collaboration where the server only sees ciphertext
Cross-tenant deal room: Buyer, Seller, and Law Firm each keep their own tenant. The shared documents, Q&A, and tasks live in one private Haven workspace, while the server only ever sees ciphertext.
Three independent tenants - one shared, end-to-end encrypted workspace. Cross-tenant Virtual Views combine each party's data into a single deal dashboard.
MindooDB Haven DAG explorer showing a document's full change graph with branches and a merge, plus a side panel with the materialized state, change author, timestamp, and the JSON of the affected fields
DAG explorer: every change is a signed node. Branches show concurrent edits, merge nodes show how Automerge resolved them - the audit trail every regulator asks for, built in.
Tamper-evident audit trail comes for free: every signed change is a node in the DAG, with author, timestamp, and per-field diff.
New podcast episode
Zero-Trust Collaboration with MindooDB Haven

Two AI hosts · ~23 min · generated by NotebookLM

A relaxed deep-dive into how Haven turns MindooDB into a browser-based workspace: end-to-end encrypted data with keys that never leave your device, local replicas for fast offline work, CRDT-based merging with a tamper-evident change history, strictly separated multi-tenant workspaces, custom apps, and virtual views that combine data across contexts. An entertaining and accessible introduction to the platform.

Download episode
One surface for daily work

Your workspace, your way

Pages, Chicklets, and groups let you arrange databases, applications, notes, web content, and media exactly the way your team thinks. Haven becomes the calm home screen for your encrypted data.

Workspace & Apps →
  • Multiple workspace pages reorderable like tabs, plus a Start page for a full overview.
  • Draggable, resizable tiles for databases, apps, notes, web, media, and Mermaid diagrams.
  • Search by database, tenant, tag, or server so nothing gets lost.
  • Database browser with CRUD, revision compare, and drag-and-drop file attachments.
  • Rich file preview for Office, images, audio, and video - MP4 even transmuxed on the fly.
MindooDB Haven welcome screen in light mode
Drag to compare Haven light and dark mode.
See it in action

A real workspace, ready for everyday work

Haven is not a concept mockup. It is a working product that already brings together navigation, workspace organization, search, database access, and local-first workflows in the browser.

Click the workspace screenshot to inspect a much taller Haven page with notes, media, running apps, mind maps, Kanban boards, and Mermaid tiles in one real workspace.

Real workspace

Full mixed-tile Haven workspace

Scroll inside the frame or jump directly to a region:

Long Haven workspace screenshot showing notes, media, embedded web content, running apps, a mind map, a Kanban board, and Mermaid diagrams in one large workspace page
Build on Haven

A real app platform, not just a launcher

Applications can run embedded in the Haven workspace or in their own tab, access selected databases and views, and ship as either externally hosted web apps or Haven-hosted bundles served offline by the service worker. And you do not have to write one to get one: the App Builder turns a description into a deployed, installed app.

Apps & SDK →
  • App Builder - no coding required. Describe the app your team is missing and Haven's own builder app sets up the project, publishes it to the web, has an AI agent write it, and installs it in Haven. What you get is a full MindooDB App with its own source code, free to use every platform feature - and asking for the next feature is just another brief. You bring a GitHub, Cloudflare, and Cursor account; the builder itself is open source.
  • MindooDB App SDK with launch context, live events, documents, attachments, and Virtual Views.
  • Capability-based security - Haven decides what every app can see and do.
  • Online or offline - hosted bundles run even when the network is gone.
  • Nine apps in the store - five first-party productivity apps you install from Haven (Mindoo Vega, for mind mapping, Kanban, Gantt scheduling and spreadsheet reporting on the same project nodes, Mindoo TodoManager, for team todos, Mindoo TeamEdit, a collaborative editor for markdown and Word documents that lets several people edit the same .docx on several devices at once without a Word licence, Mindoo TeamSketchbook, a collaborative multi-page hand-drawing sketch book with paper styles and stroke-level merging, and Mindoo Teacher's Desk, a complete digital workspace for teachers), one open-source collaborative editor that demonstrates the SDK's granular patch APIs (Mindoo TeamGrid, a collaborative spreadsheet with around 280 Excel-compatible formulas, charts, XLSX round-trip, and Virtual View Sheets that pull data from cross-tenant Haven views into ordinary worksheets), a beautiful responsive weather tile (Mindoo Weather) that adapts to the tile size and showcases the SDK's UX surface, and the open-source MindooDB App SDK example to fork as the starting point for your own app, plus the App Builder itself.
  • Or bring your own toolchain - fork the starter template, or feed /llms-full.txt and the example repo to the coding agent you already use.
Mindoo Vega Mind map and Kanban in one embedded app
Mindoo Vega embedded in Haven showing a mind map with nested projects, sprints, documents, and tasks
Mindoo Vega embedded in Haven showing the related Kanban board view for the selected project
TodoManager Light and dark mode team task boards
Mindoo TodoManager embedded in Haven showing a light theme task board grouped by importance and due date
Mindoo TodoManager embedded in Haven showing the same task board in dark mode
Mindoo TeamEdit Collaborative markdown editor with character-level merging
Mindoo TeamEdit embedded in Haven, showing a markdown document being edited on the left and the rendered live preview pane on the right
Mindoo TeamEdit showing a Mermaid timeline diagram authored as a fenced code block and rendered live in the preview pane

MindooDB Apps

Mindoo Vega mind map for an Aurora product launch project, where each topic node shows an attached panel with assignee, status, priority, start and end date, progress, and planned versus actual effort and cost
Mindoo VegaDesktop
Every node carries its task data

A mind map where every node carries its task data: assignee, status, priority, dates, progress, effort and cost.

133
Private by design

Encrypted from the first keystroke

Haven inherits MindooDB's trust model. Data is encrypted on the client before it ever leaves the device, apps run in sandboxed iframes with granular permissions, and the DAG explorer makes collaboration auditable.

Security & Privacy →
Haven Configure application dialog showing runtime mode, hosting mode, launch parameters, and per-database capabilities (write, delete, history, attachments, views) with a tooltip describing the attachments permission
Configure application: per-database capability grid (write, delete, history, attachments, views) plus launch parameters and database mappings.
Haven Sync page listing tenant databases with direction indicators and a Sync menu open on the Docs only, no attachments option
Sync page: per-database push-only, pull-only, or bidirectional sync, with the option to transfer documents only or documents plus attachments.
  • End-to-end encryption with client-held keys and no plaintext on infrastructure.
  • Sandboxed apps on separate origins; hosted bundles get an even stricter opaque-origin sandbox.
  • DAG explorer turns Automerge merges into a navigable, auditable history.
  • Flexible sync - push-only, pull-only, or bidirectional per setup, and per database you can choose whether to transfer documents plus attachments or documents only for leaner, faster syncs.
  • Built-in backup of in-browser data, plus Virtual Views as a secure analytical layer.
Where your data lives

Local, demo, or your own server

Haven Community works in three topologies. Choose the one that matches your workflow - you can move between them without changing clients.

Deployment options →
Local only
Fully in your browser

Create tenants and databases entirely offline. No server, no sync - ideal for personal use, drafts, and offline demos.

Mindoo demo server
Try team features

Push a local tenant to the hosted demo server and invite real collaborators. Demo data is wiped periodically - it is for evaluation, not production.

Self-hosted
Your own server

Point Haven at a MindooDB server you run. See README-server.md for setup.

Latest from the blog

MindooDB and Haven updates

Product updates and implementation notes from the MindooDB ecosystem.

Read all posts →

September 23, 2026

The Haven App Builder - describe the app your team is missing, and an AI writes it

Haven has been extensible through apps for a while: the MindooDB App SDK, a set of context files a coding agent can read, and a reference app to fork. That works - and it still asks you to care about where the code lives, who hosts it, and how the result reaches Haven. The new App Builder, itself an app in Haven's App Store, removes all of it. Connect GitHub, Cloudflare and Cursor once, then type a name and a few sentences about the app you are missing and press one button: the builder creates a private repository from a starter template, writes your brief into it, reserves a web address on Cloudflare, wires push-to-deploy, waits for the app to answer, hands it to Haven for installation, and sets a Cursor cloud agent to work - which you can then watch draw an icon, write the app and click through it in a browser. What comes out is an ordinary MindooDB App with its own repository and its own address, and it is safe to run because none of Haven's app isolation changed: sandboxed iframe, logical database ids, permissions you granted at install time, and a network allowlist that blocks anything the app was not allowed to call.

September 22, 2026

Peer-to-peer sync between Haven clients - and reaching the MindooDB server in the cupboard

Haven clients can now sync directly with each other over the Iroh network, with no server in the middle: two devices of the same tenant converge device to device, carry on collaborating while the server is down, and hand over the complete signed history afterwards. It arrived as the side effect of solving a duller problem. The crazy-hardware series proved that a MindooDB server fits inside a phone, an Orange Pi and a Wi-Fi router - and then left every one of them sitting at a LAN address. At Local First Conf in Berlin I watched Brendan O'Brien present Iroh: endpoints identified by public key rather than DNS name, QUIC, relays when NAT gets in the way, and a Rust library that compiles to WebAssembly. Both the MindooDB server and the Haven client now speak it, so pasting a ticket into Haven makes the box in the cupboard reachable with no DynDNS, no port forward and no certificate. And once that runtime was in the browser, peer-to-peer sync was a change of argument rather than a change of code path.

September 12, 2026

MindooDB on crazy hardware, part three - a server inside the Wi-Fi router

First an emulated x86_64 VM on an iPhone, then an Orange Pi Zero 3W with eight cores and 6 GB of RAM. This time the host is the box that was already in the room doing another job: a GL.iNet Flint 2 AX6000 Wi-Fi router - four ARM64 cores, 1 GB of RAM, 8 GB of eMMC and OpenWrt. It was the bumpiest setup of the three, and both potholes were OpenWrt's: Docker's bridge DNS could not resolve the npm registry during the build, and nftables would not hairpin the published port afterwards. Both are now handled by serversetup.sh itself. After that the server minted its identity in 1661 milliseconds, and Haven pushed a Teacher's Desk tenant to the thing that hands out our Wi-Fi.