Skip to content

Security & trust

Clear controls, careful claims.

This page describes safeguards represented in the current repository. Servaton does not claim SOC 2, HIPAA, PCI DSS, GDPR, CCPA, or another certification or compliance status here.

01

Account separation

Business data access is scoped through authenticated membership and tenant context. Database row-level security is represented in the production architecture.

02

Role-based access

Owner, staff, and platform-support paths use explicit authorization. Support sessions are time-limited and audited.

03

Authentication controls

The product includes password hashing, email verification, session controls, recovery tokens, throttling, and multi-factor authentication support.

04

Sensitive data protection

Registered sensitive fields and provider credentials use versioned application-layer encryption. Secrets remain server-side and are screened from frontend bundles.

05

Provider boundaries

Voice, messaging, scheduling, and automation connections require explicit configuration. External provider calls can be disabled, and webhook paths implement signature and replay controls.

06

Data lifecycle

Configurable retention, legal-hold controls, customer export, and deletion workflows exist. Destructive production retention awaits approved legal and operating policy.

Responsible questions

Privacy, security, export, or deletion.

Email hello@servaton.app. Do not include secrets or customer content. Identity and account authority are verified before account-specific action.