← All legal documents

Trust and security

Security Overview

An implementation-grounded overview of controls observed in the Bavio repository, without certification or hosting claims.

Draft status · Last updated: 2026-09-14

On this page

Scope and statusTenant isolationSecrets and credentialsTransport and endpointsAccess and authenticationExecution evidenceInfrastructure and providersIncidents and reportingSecurity review

1. Scope and status

This document is a draft for founder and legal review. It is not legal advice and does not create a commitment until approved and published.

This overview describes controls observed in the current repository. It is not a certification, audit report, uptime commitment, or guarantee of security for every deployment.

2. Tenant isolation

Tenant-aware services, authorization checks, and selected PostgreSQL RLS protections are used in platform paths. Customers must still configure Workspace users, provider access, Actions, Workflows, and webhook destinations carefully.

3. Secrets and credentials

Environment-based secrets, signed provider callbacks, signed outbound webhooks, and encrypted webhook-secret storage are present in supported paths. Do not expose service-role keys or provider secrets in client code.

4. Transport and endpoints

Supported HTTPS integrations and endpoint validation are used where implemented. Provider and network behavior can vary; this page does not claim a universal TLS version or end-to-end encryption for every data path.

5. Access and authentication

Authentication callbacks, session behavior, tenant checks, and route-level authorization are part of the observed application. Customers are responsible for user access, credential hygiene, and prompt reporting of unauthorized activity.

6. Execution evidence

Action and Workflow evidence records technical execution state. It does not prove a business outcome, caller intent, legal basis, or correctness of AI interpretation.

7. Infrastructure and providers

Supabase, Twilio, configurable model/speech providers, email, and billing paths may process data depending on configuration. Hosting region, transfer mechanism, certifications, and provider contract terms require confirmation.

8. Incidents and reporting

Report suspected security issues to [SECURITY_EMAIL]. Incident response, notification timing, recovery objectives, and support targets are [INCIDENT_NOTIFICATION_PERIOD], [RTO], [RPO], and [SUPPORT_POLICY].

9. Security review

The current package intentionally does not claim ISO, SOC, HIPAA, GDPR certification, sovereign hosting, or a fixed uptime percentage. Those statements require independent evidence and approval.

Related policies

Privacy ↗Acceptable use ↗Billing ↗Recording ↗Telecommunications ↗