Account separation
Business data access is scoped through authenticated membership and tenant context. Database row-level security is represented in the production architecture.
Security & trust
This page describes safeguards represented in the current repository. Servaton does not claim SOC 2, HIPAA, PCI DSS, GDPR, CCPA, or another certification or compliance status here.
Business data access is scoped through authenticated membership and tenant context. Database row-level security is represented in the production architecture.
Owner, staff, and platform-support paths use explicit authorization. Support sessions are time-limited and audited.
The product includes password hashing, email verification, session controls, recovery tokens, throttling, and multi-factor authentication support.
Registered sensitive fields and provider credentials use versioned application-layer encryption. Secrets remain server-side and are screened from frontend bundles.
Voice, messaging, scheduling, and automation connections require explicit configuration. External provider calls can be disabled, and webhook paths implement signature and replay controls.
Configurable retention, legal-hold controls, customer export, and deletion workflows exist. Destructive production retention awaits approved legal and operating policy.
Responsible questions
Email hello@servaton.app. Do not include secrets or customer content. Identity and account authority are verified before account-specific action.