How It WorksEmployersCreators

Security & Privacy

Your employees' trust is our product's foundation.

🛡️DPA Ready
CCPA Compliant
🌐GDPR Ready
🔒AES-256
🗄️Row-Level Security
🙈Aggregate Only
🕒SOC 2 Planned

Employers never see individual employee data. Ever.

We don't sell your data. We don't advertise. We don't share across companies.

DATA PROTECTION

What ORVI Collects
Email
Display name
Preferences
Check-in data
Card interactions
Opt-in HealthKit
What Employers See
Total enrolled
WAU/DAU
Aggregate check-in rate
Pillar engagement
NOTHING individual
What ORVI Never Does
Never shows individual data
Never sells data
Never advertises
Never shares across companies

TECHNICAL SECURITY

MeasureDetail
Encryption in transitTLS 1.3
Encryption at restAES-256 (Supabase managed)
AuthEmail OTP, short-expiry JWTs
Data isolationRow-Level Security, company_id enforcement
API securityCloudflare WAF, rate limiting
Breach notification24 hours (per DPA)
Data retentionActive during subscription, deleted within 30 days of termination
Data portabilityFull JSON export endpoint

COMPLIANCE FRAMEWORK

FrameworkStatus
HIPAANot directly applicable — standalone wellness app. HIPAA-aligned practices adopted voluntarily.
SOC 2 Type IPlanned within 6 months of first paid contract
GDPRReady — DPA with Article 28 clauses, data subject rights implemented
CCPA/CPRACompliant — no data selling, consumer rights implemented
ADACompliant — participation voluntary, no health-contingent incentives
PCI DSSHandled by Stripe — ORVI never stores card data

DATA PROCESSING AGREEMENT

We provide a pre-signed Data Processing Agreement to all pilot clients.

Sub-processors:

SupabaseOpenAIAnthropicUpstashPostHogStripeFirebaseMuxCloudflare

Security questions? Email security@orvi.ai