Security and Data Protection
The controls below are implemented in the current Oqelvia application.
Authentication
Email and password or Google sign-in. Workspace pages require a valid signed-in session; signed-out visitors are sent to sign-in.
Password protection
Passwords are hashed by the authentication service, require at least 8 characters, and are checked against known leaked-password lists.
Role-based access
Every workspace member has a stored role (the creator is the owner). Membership is recorded server-side and cannot be edited from the browser.
Workspace data isolation
Database row-level security policies ensure products, notifications, and settings can only be read by members of the owning workspace.
Encryption in transit and at rest
All traffic uses HTTPS/TLS. Data is stored in a managed database platform that encrypts storage at rest.
Secure hosting
The application runs on managed cloud infrastructure; privileged credentials are held server-side and never shipped to the browser.
Input validation
Forms are validated in the browser and again on the server and in the database, with length limits, spam traps, and duplicate protection.
Logging
Authentication events and server requests are logged by the hosting platform for troubleshooting and abuse investigation.
Data deletion
Deleting a workspace removes its products. Account deletion is handled on request via the security review form.
Incident contact
Report suspected vulnerabilities or incidents through the security review form; each report receives a stored reference number.
Need more detail for procurement?
Send your questionnaire or questions and we'll respond by email.
Request a Security ReviewOqelvia has not yet obtained third-party security certifications or audits. Backup schedule and recovery objectives will be published once confirmed.