Security and trust

Keep project access clear as the team grows

PVspark combines verified identity, organization boundaries, role-based access, audit history, private file handling, and recoverable hosted infrastructure.

Identity and session controls

The hosted application uses standards-based OIDC sign-in, verified email, multi-factor support, controlled session revocation, and provider logout.

Tenant separation

Customer membership and organization status are checked by the application and reinforced by PostgreSQL row-level security.

Least-privilege access

Customer roles, platform administration, scoped API credentials, and reason-bound time-limited support are distinct capabilities.

Data protection

Hosted databases and object storage use encryption, controlled credentials, versioning where appropriate, and malware scanning for supported uploads.

Monitoring and response

Structured logs, health checks, operational metrics, alerts, trace correlation, and incident procedures support the hosted environment.

Recovery

Database point-in-time recovery, object-version recovery, deployment rollback, and identity restore paths have documented verification boundaries.

This overview describes implemented controls, not a third-party certification. Detailed security information is shared deliberately during security review. Report a suspected vulnerability privately to security@pvspark.com; do not include live customer data in an initial report.

See PVspark in action

Discuss your security requirements

We will map access, data, support, and recovery expectations before live project use.

Essential security and preference storage remains available. Optional analytics is off unless you allow it. See cookies and storage.