Skip to main content
Porvio
ProductWorkflowArticlesPricingSecurity
Sign inCreate workspace →
Menu
ProductWorkflowArticlesPricingSecurity
Sign inCreate workspace

Trust and safety

Security

Implemented safeguards, shared responsibilities, and a private path for responsible vulnerability reporting.

UpdatedJuly 28, 2026

Ask a question

On this page

  1. 01Security approach
  2. 02Controls implemented in Porvio
  3. 03Infrastructure and provider controls
  4. 04Security assurances and scope
  5. 05Protect your workspace
  6. 06Report a vulnerability privately
  7. 07Research boundaries
  8. 08Suspected privacy or account incident
Back to top ↑
Sections8
  1. 01Security approach
  2. 02Controls implemented in Porvio
  3. 03Infrastructure and provider controls
  4. 04Security assurances and scope
  5. 05Protect your workspace
  6. 06Report a vulnerability privately
  7. 07Research boundaries
  8. 08Suspected privacy or account incident

Use patient information only in an approved workflow.

Before submitting patient information, your organization must confirm its lawful authority, required notices and consent, privacy and security review, provider approvals, retention instructions, and any required written agreement with Porvio. Do not use Porvio for patient information when those requirements are not in place.

01Security approach

Porvio uses layered technical and workflow controls to reduce the risk of unauthorized access, unsafe files, cross-organization disclosure, and unreviewed AI content. Security is shared: Porvio protects the Service, organizations manage their people and records, and every user must protect their account and device.

02Controls implemented in Porvio

  • Account creation requires email verification, password reset uses a short-lived email code, and optional email two-factor authentication adds a second sign-in step. Support administration requires two-factor authentication.
  • Public backend functions resolve the signed-in identity and check active organization membership and role server-side.
  • Clinical records are organization-scoped, and file identifiers are not treated as authorization.
  • Recording consent must be marked granted before audio upload or AI processing begins.
  • Audio uploads require an authenticated, short-lived claim; enforce the approved origin; inspect the file signature; and enforce a 25 MiB and 90-minute maximum.
  • Upload and AI workflows have rate, concurrency, state-transition, and retry boundaries.
  • Model credentials and deployment keys remain server-side rather than in the browser bundle.
  • Audit events record actor, time, action, resource, and result without intentionally duplicating full clinical content.
  • Generated content is validated, displayed as a draft, and separated from clinician approval.

03Infrastructure and provider controls

Connections use encrypted transport. Porvio keeps service credentials out of the browser, stores structured data and files in private managed services, and authorizes each application and file request. Cloudflare publishes its current platform controls through its Trust Hub.

Those are provider-reported controls. They do not make Porvio end-to-end encrypted, prove Canadian residency, or automatically satisfy a clinic’s legal obligations. Vendor contracts and production configuration remain part of security review.

04Security assurances and scope

No product control or provider assurance makes an organization automatically compliant with PHIPA, PIPEDA, HIPAA, or another law. Compliance depends on the organization’s role and use, configuration, contracts, policies, training, notices, consent, and documented risk assessment. Porvio does not claim a SOC 2 attestation, ISO certification, HIPAA certification, or similar independent assurance unless a current written statement expressly says so.

Organizations must confirm that Porvio’s retention, export, deletion, backup, incident-response, support-access, and offboarding capabilities meet their requirements before placing patient information in the Service.

05Protect your workspace

  • Use a unique password and protect the email account tied to Porvio.
  • Do not share accounts, passwords, invitation links, or browser sessions.
  • Keep devices, browsers, and operating systems current and encrypted.
  • Sign out of shared devices and remove access promptly during offboarding.
  • Grant only the minimum role required for each person.
  • Never send patient data, secrets, or access tokens through ordinary support email.

06Report a vulnerability privately

Email [email protected] with the subject “Private security report” and ask for a secure reporting channel. In that first message, include only your contact details and a brief, non-sensitive description. Do not put exploit details, credentials, patient information, or clinical records in a public issue or ordinary email.

When safe, include:

  • the affected route, component, commit, or deployment;
  • reproduction steps using only non-sensitive test data and your own account;
  • the likely impact and required preconditions;
  • screenshots or logs with tokens and personal information removed; and
  • a safe way to contact you.

07Research boundaries

Do not access, copy, change, or retain real patient data. Do not perform denial-of-service testing, social engineering, physical attacks, credential stuffing, automated destructive testing, or testing against an account you do not own. Stop immediately if real personal information becomes visible and report only the minimum needed to find the exposure. Coordinated disclosure timing will depend on severity, exploitation risk, and remediation readiness.

08Suspected privacy or account incident

If you suspect unauthorized access, sign out where possible, secure the affected email account and device, preserve relevant evidence without copying clinical content, and contact [email protected]. Send privacy concerns to [email protected]. Do not delay emergency or patient-safety action while waiting for Porvio support.

Return to top ↑
Porvio

The work around care,finally connected.

Clinical documentation that keeps consent, review, and the final decision with the clinician.

Available to eligible Ontario healthcare organizations.
ExploreProductWorkflowArticlesPricing
TrustSecurityPrivacyResponsible AIAccessibility
AccountSign inCreate workspaceEmail support

© 2026 Porvio

TermsCookies & storage