Security

How we handle your data.

Zuvaria holds institutional records — agreements, policies, approvals, decisions. Here is how that data is protected, in plain terms.

Encrypted in transit and at rest

Every connection uses TLS. Everything stored — records, uploaded files, attachments — is encrypted at rest by the hosting platform.

Access is enforced in the database

Permissions are evaluated by the database on every query, not just hidden in the interface. A request for a record someone is not entitled to see returns nothing, whatever the request looks like.

Role-based by default

People see what their role gives them. Restricted documents stay with the committee or office that owns them, and sharing something wider is a deliberate act.

Actions are logged

Changes to records — who changed what, and when — are written to an audit trail, so the history of a decision survives the person who made it.

Hosted in the United States

Data is stored on US infrastructure, and each institution’s data is isolated from every other institution’s.

Your data stays yours

You own what you put in. You can export your records on request, and if you ever leave, you leave with them.

Reviewing us?

Send us your security questionnaire or vendor review checklist and we’ll complete it. If your IT office needs something specific before a pilot can move, ask — it is a faster conversation than a page like this one.

Email us

Or write to hello@zuvaria.com.