Security

Security and Data Protection

The controls below are implemented in the current Oqelvia application.

Authentication

Email and password or Google sign-in. Workspace pages require a valid signed-in session; signed-out visitors are sent to sign-in.

Password protection

Passwords are hashed by the authentication service, require at least 8 characters, and are checked against known leaked-password lists.

Role-based access

Every workspace member has a stored role (the creator is the owner). Membership is recorded server-side and cannot be edited from the browser.

Workspace data isolation

Database row-level security policies ensure products, notifications, and settings can only be read by members of the owning workspace.

Encryption in transit and at rest

All traffic uses HTTPS/TLS. Data is stored in a managed database platform that encrypts storage at rest.

Secure hosting

The application runs on managed cloud infrastructure; privileged credentials are held server-side and never shipped to the browser.

Input validation

Forms are validated in the browser and again on the server and in the database, with length limits, spam traps, and duplicate protection.

Logging

Authentication events and server requests are logged by the hosting platform for troubleshooting and abuse investigation.

Data deletion

Deleting a workspace removes its products. Account deletion is handled on request via the security review form.

Incident contact

Report suspected vulnerabilities or incidents through the security review form; each report receives a stored reference number.

Need more detail for procurement?

Send your questionnaire or questions and we'll respond by email.

Request a Security Review

Oqelvia has not yet obtained third-party security certifications or audits. Backup schedule and recovery objectives will be published once confirmed.