Legal
Security & Trust Overview
Public-facing summary of current security and trust posture.
ALVERA SECURITY & TRUST OVERVIEW
Public-facing summary of current security and trust posture.
Provider: Sean Dotts d/b/a Alvera
Version: 2026.05.08-enterprise.vFinal
Effective Date: May 8, 2026
Contact: Sean.dotts@gmail.com
1. Security Philosophy
Alvera is designed as a controlled-access business platform emphasizing confidentiality protection, restricted evaluation governance, auditability, export governance, and commercially reasonable security controls. This overview describes current security practices without creating a guarantee of perfect security.
2. Identity and Access
Alvera uses Supabase Auth for authentication, including email/password login, Google OAuth, and MFA support. The Service uses workspace roles and role-based access controls. Higher-risk contexts may require MFA. Alvera does not currently support SSO/SAML.
3. Restricted Evaluator Controls
Alvera supports restricted evaluator classifications and high-risk workspace controls. Restricted evaluators may be required to accept additional terms and may be subject to enhanced restrictions, watermarking, export limitations, and audit logging.
4. Upload Security
Supported upload workflows use asynchronous upload security scanning. New uploads may remain unavailable until scanning completes with a clean status. Non-clean uploads do not receive standard signed access URLs in normal product workflows. Infected uploads may be removed from storage. Alvera supports integration with ClamAV-compatible scanning infrastructure when configured and uses baseline file safety checks where applicable.
5. Storage and File Access
Uploaded files are stored using private storage patterns and signed access workflows. Files are not intended to be exposed through normal product open actions until applicable scan-state and authorization checks are satisfied.
6. Export Governance
Major export workflows may be governed by server-side authorization, role checks, restricted evaluator restrictions, high-risk approval behavior, watermark metadata, rate limits, and audit logging. Clean upload metadata may be retained in admin backup contexts for restore or recovery purposes.
7. Auditability and Evidence
Alvera preserves operational audit records, including legal acceptance evidence, access events, export events, upload scanning records, evaluator events, security events, and legal hold events. Legal acceptance records include versioning, hashes, rendered snapshots, context, and related metadata.
8. Infrastructure Providers
Alvera currently uses Supabase, Vercel, Stripe, and Google services for core infrastructure, authentication, storage, billing, hosting, OAuth, calendar, mapping, places, and geocoding functionality.
9. Security Claims Not Made
Alvera does not currently claim SOC 2 certification, ISO 27001 certification, SSO/SAML support, full DLP, tamper-proof evidence, malware-free uploads, zero-day protection, or enterprise-ready security operations.
10. Contact
Security questions may be directed to Sean.dotts@gmail.com.
