LEGAL AND TRUST
Security and trust
Version 1 · updated 2026-10-06
Written in plain language and updated as the service grows. Questions: [email protected]
What protects your data today, what we have not done yet, and how to tell us about a problem. Each statement here describes something the product does and the tests check.
Your workspace is separate
- Every record and every file belongs to one workspace, and every request is checked against it. Another workspace's identifier answers “not found”, never “forbidden”.
- The separation is also enforced in the database itself: a record cannot point at another workspace's data, and a stored file's location must lie inside its own workspace's folder.
- Roles decide what a person can do in a workspace (view, generate, export, delete, manage billing), and are checked on every action.
Your files are private
- Uploads and exports sit in private storage. There is no public link to any of them.
- Downloads use signed links that expire within minutes and are created only after the request is authorised again.
- Storage locations are generated by the server from validated identifiers, never accepted from the browser.
- You choose how long files are kept, and removal really deletes them.
The numbers are checked
- Findings are computed by ordinary code, not by the language model. The model only explains the results.
- Every figure, date and name in a report is checked by code against the computed evidence. A statement that fails is rewritten or dropped, and a report says plainly when it is only partly verified.
- Statements about cause are rejected unless they are labelled as possibilities.
- Your data is treated as data, never as instructions: text inside a spreadsheet cannot give the model orders.
Accounts and abuse
- Passwords are stored only as salted hashes. Sign-in with Google or GitHub is available.
- An account that signs in with a password must first prove its email address, and can turn on two-step verification with an authenticator app, with one-time recovery codes. A code can be used only once.
- You can end every session on every device at once, and changing or resetting your password does the same. A session stolen earlier stops working at that moment.
- Links we email (to confirm an address or reset a password) work once, expire, and are stored only as a hash.
- Sensitive actions are rate-limited and every input is validated.
- Responses that carry your data are never cached by browsers or shared proxies.
- Important actions leave an audit record, with identifiers and never with the content of your data. The database refuses to edit or delete these records, apart from detaching your name when you delete your account and removing records after about 13 months.
What we have not done yet
We are honest about this: Provetale does not hold a security certification such as SOC 2 or ISO 27001. Being ready for one is a goal we are working towards, not something we claim. Planned but not done: database-level row security as a second layer (under evaluation) and an independent security review. The services that handle data, with their regions, are listed on the “Where your data goes” page.
Tell us about a problem
If you think you have found a vulnerability, write to [email protected] with what you found and how to reproduce it. Please do not access other people's data or disrupt the service while testing, and give us reasonable time to fix it before you share it. We will acknowledge your report and keep you informed.