Your data is handled with
the care it deserves
Provvy automates access to your most sensitive systems. Here's exactly how we keep company and employee data safe every step of the way.
Encryption at rest & in transit
All data is encrypted with AES-256 at rest and TLS 1.3 in transit. Employee records, credentials, and workflow configurations are never stored in plaintext.
Secure integrations
Provvy never stores employee passwords. Integrations connect via OAuth, API key, or service account — always with the minimum permissions required. OAuth tokens are short-lived and revocable from your identity provider. API keys and service account credentials are encrypted with customer-managed keys and never stored in plaintext.
Least-privilege access
Provvy requests only the minimum OAuth scopes needed for each integration. Tokens are stored in a dedicated encrypted key-value store. Customers can revoke Provvy's access from their identity provider at any time.
Isolated tenant data
Each organisation's data is logically isolated per tenant, enforced through row-level security at the database layer. Your employee data is never returned in another customer's queries.
Immutable audit logs
Every provisioning and deprovisioning action is recorded in an append-only audit log with timestamps and actor identity. Logs cannot be edited or deleted — even by Provvy staff.
Dry-run before execution
Every workflow produces a plain-English dry-run report before anything runs. You review exactly what will change across every tool — nothing executes without your explicit approval.
Breach notification
In the unlikely event of a security incident, affected customers are notified without delay in compliance with Quebec Law 25 and PIPEDA, with a full incident report to follow.
SOC 2 readiness
Provvy's security controls are designed to align with SOC 2 Trust Service Criteria for security, availability, and confidentiality. Formal certification is on our roadmap.
Security at a glance
Key technical facts about how Provvy stores and processes your data.
Security questions or responsible disclosure? security@provvy.app
Built for organisations that take privacy seriously
Provvy is designed from the ground up to meet the requirements of Canadian privacy law — giving IT teams the assurances they need before deploying.
Data handling
- Application data is encrypted at rest and logically isolated per tenant.
- Infrastructure hosted in AWS Canada (Central). Your data stays in Canada.
- Provvy does not sell, rent, or share customer data with third parties.
- Designed to meet the requirements of Quebec Law 25, PIPEDA, and Canadian privacy legislation.
Privacy Compliance
- Provvy acts as a data processor — your organization retains full data ownership.
- Data Processing Agreement (DPA) available on request.
- Supports data access requests and right-to-erasure under Law 25 and PIPEDA.
- Breach notification to the CAI and OPC without undue delay as required by Law 25 and PIPEDA.
- Subprocessor list available; customers are notified of changes.
Need a DPA or documentation for your IT team?
We provide Data Processing Agreements and architecture documentation for organizations that need them before deploying.
Frequently asked questions
Common questions about how we handle your data and protect your privacy.