Security approach
Porvio uses layered technical and workflow controls to reduce the risk of unauthorized access, unsafe files, cross-organization disclosure, and unreviewed AI content. Security is shared: Porvio protects the Service, organizations manage their people and records, and every user must protect their account and device.
Controls implemented in Porvio
- Account creation requires email verification, password reset uses a short-lived email code, and optional email two-factor authentication adds a second sign-in step. Support administration requires two-factor authentication.
- Public backend functions resolve the signed-in identity and check active organization membership and role server-side.
- Clinical records are organization-scoped, and file identifiers are not treated as authorization.
- Recording consent must be marked granted before audio upload or AI processing begins.
- Audio uploads require an authenticated, short-lived claim; enforce the approved origin; inspect the file signature; and enforce a 25 MiB and 90-minute maximum.
- Upload and AI workflows have rate, concurrency, state-transition, and retry boundaries.
- Model credentials and deployment keys remain server-side rather than in the browser bundle.
- Audit events record actor, time, action, resource, and result without intentionally duplicating full clinical content.
- Generated content is validated, displayed as a draft, and separated from clinician approval.
Infrastructure and provider controls
Connections use encrypted transport. Porvio keeps service credentials out of the browser, stores structured data and files in private managed services, and authorizes each application and file request. Cloudflare publishes its current platform controls through its Trust Hub.
Those are provider-reported controls. They do not make Porvio end-to-end encrypted, prove Canadian residency, or automatically satisfy a clinic’s legal obligations. Vendor contracts and production configuration remain part of security review.
Security assurances and scope
No product control or provider assurance makes an organization automatically compliant with PHIPA, PIPEDA, HIPAA, or another law. Compliance depends on the organization’s role and use, configuration, contracts, policies, training, notices, consent, and documented risk assessment. Porvio does not claim a SOC 2 attestation, ISO certification, HIPAA certification, or similar independent assurance unless a current written statement expressly says so.
Organizations must confirm that Porvio’s retention, export, deletion, backup, incident-response, support-access, and offboarding capabilities meet their requirements before placing patient information in the Service.
Protect your workspace
- Use a unique password and protect the email account tied to Porvio.
- Do not share accounts, passwords, invitation links, or browser sessions.
- Keep devices, browsers, and operating systems current and encrypted.
- Sign out of shared devices and remove access promptly during offboarding.
- Grant only the minimum role required for each person.
- Never send patient data, secrets, or access tokens through ordinary support email.
Report a vulnerability privately
Email [email protected] with the subject “Private security report” and ask for a secure reporting channel. In that first message, include only your contact details and a brief, non-sensitive description. Do not put exploit details, credentials, patient information, or clinical records in a public issue or ordinary email.
When safe, include:
- the affected route, component, commit, or deployment;
- reproduction steps using only non-sensitive test data and your own account;
- the likely impact and required preconditions;
- screenshots or logs with tokens and personal information removed; and
- a safe way to contact you.
Research boundaries
Do not access, copy, change, or retain real patient data. Do not perform denial-of-service testing, social engineering, physical attacks, credential stuffing, automated destructive testing, or testing against an account you do not own. Stop immediately if real personal information becomes visible and report only the minimum needed to find the exposure. Coordinated disclosure timing will depend on severity, exploitation risk, and remediation readiness.
Suspected privacy or account incident
If you suspect unauthorized access, sign out where possible, secure the affected email account and device, preserve relevant evidence without copying clinical content, and contact [email protected]. Send privacy concerns to [email protected]. Do not delay emergency or patient-safety action while waiting for Porvio support.