Security & Trust

Your data is handled with the care it deserves

Provvy automates access to your most sensitive systems. Here's exactly how we keep company and employee data safe every step of the way.

Encryption at rest & in transit

All data is encrypted with AES-256 at rest and TLS 1.3 in transit. Employee records, credentials, and workflow configurations are never stored in plaintext.

Secure integrations

Provvy never stores employee passwords. Integrations connect via OAuth, API key, or service account — always with the minimum permissions required. OAuth tokens are short-lived and revocable from your identity provider. API keys and service account credentials are encrypted with customer-managed keys and never stored in plaintext.

Least-privilege access

Provvy requests only the minimum OAuth scopes needed for each integration. Tokens are stored in a dedicated encrypted key-value store. Customers can revoke Provvy's access from their identity provider at any time.

Isolated tenant data

Each organisation's data is logically isolated per tenant, enforced through row-level security at the database layer. Your employee data is never returned in another customer's queries.

Immutable audit logs

Every provisioning and deprovisioning action is recorded in an append-only audit log with timestamps and actor identity. Logs cannot be edited or deleted — even by Provvy staff.

Dry-run before execution

Every workflow produces a plain-English dry-run report before anything runs. You review exactly what will change across every tool — nothing executes without your explicit approval.

Breach notification

In the unlikely event of a security incident, affected customers are notified without delay in compliance with Quebec Law 25 and PIPEDA, with a full incident report to follow.

SOC 2 readiness

Provvy's security controls are designed to align with SOC 2 Trust Service Criteria for security, availability, and confidentiality. Formal certification is on our roadmap.

Security at a glance

Key technical facts about how Provvy stores and processes your data.

Data storedEncrypted at rest (AES-256), logically isolated per tenant
Encryption at restAES-256
Encryption in transitTLS 1.3
Access modelOAuth, API key, or service account — least-privilege only
Audit logsImmutable, append-only
Token storageDedicated encrypted store with customer-managed keys
Data residencyCanada (AWS ca-central-1)
SubprocessorsListed on request

Security questions or responsible disclosure? security@provvy.app

Data Residency & Privacy

Built for organisations that take privacy seriously

Provvy is designed from the ground up to meet the requirements of Canadian privacy law — giving IT teams the assurances they need before deploying.

🔐

Data handling

  • Application data is encrypted at rest and logically isolated per tenant.
  • Infrastructure hosted in AWS Canada (Central). Your data stays in Canada.
  • Provvy does not sell, rent, or share customer data with third parties.
  • Designed to meet the requirements of Quebec Law 25, PIPEDA, and Canadian privacy legislation.
🛡️

Privacy Compliance

  • Provvy acts as a data processor — your organization retains full data ownership.
  • Data Processing Agreement (DPA) available on request.
  • Supports data access requests and right-to-erasure under Law 25 and PIPEDA.
  • Breach notification to the CAI and OPC without undue delay as required by Law 25 and PIPEDA.
  • Subprocessor list available; customers are notified of changes.

Need a DPA or documentation for your IT team?

We provide Data Processing Agreements and architecture documentation for organizations that need them before deploying.

Contact us →

Frequently asked questions

Common questions about how we handle your data and protect your privacy.

Ready to automate with confidence?

Start free — no credit card required.

Get started free