Security
How OTVera protects your data
An equipment list with firmware versions, zones and incident plans is sensitive. OTVera is designed so the secure setting is the default one, and nothing here can be turned off by a user.
Accounts and sign-in
- Accounts are created by invitation only.
- Every account uses an authenticator app code (multifactor authentication). It cannot be turned off.
- Passwords must be at least 12 characters and are stored with the scrypt algorithm.
- Repeated failed sign-ins are slowed and locked out. Error messages don't reveal whether an account exists.
- Sessions end after an hour of inactivity. Changing your password signs out every other session.
Access control
- Every request is checked on the server against your workspace and role (viewer, editor or admin).
- Suppliers never get accounts. They receive single-use, expiring links that only show what was asked of them. Links are stored as one-way hashes.
- An activity log records who changed what and when. It can't be edited from the app.
Data protection
- All traffic uses HTTPS with HSTS.
- Uploaded documents, authenticator secrets, IP addresses, serial numbers and notes are encrypted in the database with a key stored separately from it.
- Uploads are limited to 10 MB and checked by file content, not just the name.
- Spreadsheet exports are protected against formula injection.
- Pages use a strict content security policy, anti-forgery tokens on every form, and no third-party scripts, fonts or trackers.
AI
AI features are off by default. When enabled, they receive only product names, model text, requirement wording and supplier answers. Never IP addresses, serial numbers, notes, documents or personal data.
Reporting a vulnerability
Email hello@otvera.com with "Security" in the subject. Please give us a reasonable time to fix an issue before sharing it publicly. We won't take legal action against good-faith research that avoids other customers' data.