1. Home
  2. Security

How EVOR protects your business data.

This page describes controls that exist in EVOR today, in plain language. We do not claim certifications we have not been awarded.

Workspace isolation

Every business record carries the workspace it belongs to. The server sets that value from your signed-in membership and filters every query by it — the browser or app cannot choose another workspace. Requests without a workspace return nothing.

Least-privilege roles

Roles grant actions (view, create, update, approve, export) on each kind of record, with a data scope of own, team, branch or all. Owners can edit roles; changes are audited.

Audit history

Creates, updates, status changes, approvals, deletions and sign-ins are recorded with who, when and what changed. Ordinary users cannot edit the audit log.

Sign-in protection

Passwords are stored with adaptive hashing. Repeated failed sign-ins lock the account for a period. Sessions rotate on sign-in and can be ended by the owner.

Separate customer portal

Customer portal users sign in through a separate identity and see only records the workspace has shared. They can never reach employee screens or APIs.

Files and documents

Uploads are checked for type and size and stored per workspace. Files are served only after the request is authorised. Issued documents are kept as versioned snapshots.

Approvals that cannot be bypassed

Approval rules are checked on the server. Changing an approved amount or scope invalidates the approval. Overrides need a reason and are audited.

API keys and webhooks

API keys are scoped, can expire and are shown once; only a hash is stored. Webhooks are signed so your system can verify they came from EVOR.

AI with boundaries

EVOR AI only sees records the asking person is allowed to see, never another workspace. Suggestions require confirmation before anything is saved.

Your data, your control

Workspace owners can export their records. When a subscription ends, data is retained for an export period before closure, as described in the terms.

Report a security concern

If you believe you have found a vulnerability, write to security@evor.com. Please do not test against other customers’ workspaces.

Set up your workspace in minutes.

Start with the template for your industry. Invite your team when you are ready.