Security · pilot boundaries
What the pilot does,and what it does not.
Orvero is in a private pilot on a single server for a small number of firms. This page states what is in place today, in plain terms, and what is not. Start with fictional, closed or redacted matters until your firm has reviewed it.
Invite-only accessPilot users sign in with a one-time invite code; only its SHA-256 is stored. Sessions are signed cookies, HttpOnly, Secure over HTTPS, with fixed lifetimes. A disabled user is signed out on the next request.
Tenant separationEach firm is a tenant. Every matter read, write, export and delete checks the tenant and the matter id; another tenant’s matter returns not found. This is enforced in application code on one server, not separate infrastructure.
HTTPS when hostedThe hosted pilot runs behind a TLS-terminating proxy. State-changing requests from another origin are refused.
No PHI boundaryThe pilot is not set up to hold protected health information. The workflow needs only organizational and regulatory matter documents; the upload page says so.
No advertising trackersNo third-party analytics, pixels, advertising or session replay. First-party usage events record what was opened or used, never what it contained.
Source provenanceOfficial text is captured with its SHA-256, retrieval time and version. Each fact and filing field states where it came from.
Privacy-safe errorsUnexpected errors log a reference, the route without identifiers and the error class. Never document text, facts, names or messages.
Backups and deletionHosted data lives on one persistent volume. Backups are archived with a hash manifest that can be verified; retention keeps 7 daily and 4 weekly archives. Deleting a matter removes its file, including document text and history.
Not in place, and not claimed
- SOC 2 or any other security certification
- HIPAA compliance or a business associate agreement
- Single sign-on, MFA or per-user roles within a firm
- Encryption at rest beyond the host’s encrypted volume
- Multi-region or horizontally scaled hosting
Document reading, when the server has an extraction model configured, sends that matter’s document text to the model provider, whose data terms apply. Without it, nothing is sent anywhere. Questions about the boundary: request a walkthrough. See also Privacy and Terms.