Back to legal center

Legal

Security Program / Security Exhibit

Operational security program and safeguard overview.

Version 2026.05.08-enterprise.vFinalEffective 2026-05-08

ALVERA SECURITY PROGRAM / SECURITY EXHIBIT

Operational security program and safeguard overview.

Provider: Sean Dotts d/b/a Alvera

Version: 2026.05.08-enterprise.vFinal

Effective Date: May 8, 2026

Contact: Sean.dotts@gmail.com

1. Purpose

This Security Program / Security Exhibit describes commercially reasonable administrative, technical, and operational safeguards used by Alvera to support the Service. It is intended for security review and operational transparency and does not create a guarantee of perfect security.

2. Governance

Security responsibilities are centrally managed by Sean Dotts d/b/a Alvera. Security practices may evolve as the Service, infrastructure, customer base, and risk profile mature.

3. Identity and Access Management

Alvera uses Supabase Auth for authentication and supports email/password login, Google OAuth, and MFA. The Service uses workspace roles, role-based access control, server-side authorization checks, access invalidation, and restricted evaluator classifications. SSO/SAML is not currently implemented.

4. Restricted Evaluation Controls

Restricted evaluator access may require additional legal acceptance, enhanced restrictions, export limitations, watermarking, monitoring, and audit logging. Restricted evaluators may be blocked from certain exports or functionality depending on workspace and user classification.

5. Upload Security Program

Supported upload workflows use asynchronous upload security scanning. Files may be stored first in a pending state and remain unavailable through normal product access workflows until scanning completes with a clean status. Non-clean uploads do not receive standard signed access URLs. Infected uploads may be removed from storage. The scanning architecture supports ClamAV-compatible scanning infrastructure when configured and baseline file safety checks where applicable.

6. Export Governance

Major export workflows may use server-side authorization, role checks, rate limits, restricted evaluator controls, high-risk approval behavior, watermark metadata, and audit logging. Export governance is designed to reduce unauthorized extraction and support investigations.

7. Audit Logging and Evidence

Alvera preserves records related to legal acceptance, access events, security events, export events, evaluator actions, upload scanning, legal holds, role changes, and other operational events. Legal acceptance records are designed to support append-only and tamper-evident preservation through versioning, hashes, rendered snapshots, and related metadata.

8. Storage and Infrastructure

The Service uses private storage patterns and signed access workflows for supported file access. Current core providers include Supabase, Vercel, Stripe, and Google services. Alvera may update infrastructure providers as the Service evolves.

9. Legal Hold and Retention

Certain records may be preserved under legal hold or evidence retention procedures, including legal acceptance records, audit logs, export events, upload scanning records, security events, evaluator events, and access records.

10. Limitations

Alvera does not currently claim SOC 2 certification, ISO 27001 certification, SSO/SAML support, full DLP, tamper-proof evidence, malware-free uploads, zero-day protection, or enterprise security operations equivalent to large regulated enterprises.

11. Contact

Questions may be directed to Sean.dotts@gmail.com.

Alvera