Data handling

Security & trust

How CorvaneOS protects keys, credentials and integrations.

Sign-in

Accounts are managed by Supabase Auth. Every workspace page and API route requires a signed-in session, and signed-out visitors are sent to the login page.

Keys and credentials

  • Sales integration credentials (Stripe, Razorpay, Shopify, WooCommerce) are encrypted with AES-256-GCM before they are stored and only decrypted on the server.
  • Secret API keys are shown once; CorvaneOS stores only a SHA-256 hash.
  • The AI provider key stays encrypted on the server and never reaches the browser.

Public API protections

Keys are scoped, publishable keys only work from your allowed domains, requests are rate limited and body sizes are capped. See Authentication.

Webhooks

Outgoing webhooks go only to public HTTPS endpoints and are signed with HMAC-SHA256 so you can verify they came from CorvaneOS.

Audit trail

Investor workspaces keep an append-only audit log, deal stage history and investment-committee decisions that can't be edited after the fact.

Reporting a problem

If you find a security issue, contact the CorvaneOS team privately before sharing it publicly so we can fix it quickly.