Security and data handling
This page describes what Zerqivo actually implements today. Where something is provided by an infrastructure partner rather than by Zerqivo, it is stated as such.
Authentication
Accounts sign in through a managed authentication service with email and Google sign-in. Sessions are issued as short-lived tokens; the application never stores passwords itself.
Access control
Each account holds a role inside its organization (Owner, Admin, Member, Viewer). Permissions are checked on the server for every sensitive operation, not only hidden in the interface.
Organization isolation
Documents, analyses, findings, actions, history and members are scoped to one organization. Isolation is enforced by database row-level security policies, so a request from one organization cannot read another organization's rows even if identifiers are manipulated.
Document handling
Uploaded documents are stored in a private bucket under a per-organization path and are not publicly accessible. Analysis runs on the server; AI keys are never exposed to the browser. When no AI key is configured the product runs in Demo Mode with synthetic data.
Infrastructure
The application runs on managed cloud infrastructure with data stored in the European Union region of our database provider. Encryption in transit (HTTPS) and encryption at rest are provided by those infrastructure partners.
Auditability
Organization events such as data export, retention changes, member role changes and member removal are written to an append-only activity log with a timestamp, the acting account and the affected item.
Retention and deletion
Organizations can configure a retention window and apply it to their analyses. An owner can export the organization's data and can erase the organization, which deletes its analyses and stored documents.
Sub-processors
Zerqivo relies on third-party providers for hosting, database and storage, authentication, payment processing and AI model inference. A current list is available to prospective customers on request.
Certifications
Zerqivo does not hold SOC 2, ISO 27001, GDPR certification or any government or procurement approval, and does not claim any. Certifications held by our infrastructure providers belong to those providers and are not Zerqivo certifications. Any formal compliance requirement should be reviewed with us before contracting.
Security contact
For a security review, a data-processing discussion or to report a vulnerability, contact our team.
Contact Sales