Security
How we handle your data.
Zuvaria holds institutional records — agreements, policies, approvals, decisions. Here is how that data is protected, in plain terms.
Encrypted in transit and at rest
Every connection uses TLS. Everything stored — records, uploaded files, attachments — is encrypted at rest by the hosting platform.
Access is enforced in the database
Permissions are evaluated by the database on every query, not just hidden in the interface. A request for a record someone is not entitled to see returns nothing, whatever the request looks like.
Role-based by default
People see what their role gives them. Restricted documents stay with the committee or office that owns them, and sharing something wider is a deliberate act.
Actions are logged
Changes to records — who changed what, and when — are written to an audit trail, so the history of a decision survives the person who made it.
Hosted in the United States
Data is stored on US infrastructure, and each institution’s data is isolated from every other institution’s.
Your data stays yours
You own what you put in. You can export your records on request, and if you ever leave, you leave with them.
Reviewing us?
Send us your security questionnaire or vendor review checklist and we’ll complete it. If your IT office needs something specific before a pilot can move, ask — it is a faster conversation than a page like this one.
Email usOr write to hello@zuvaria.com.