Authorisation is checked server-side against the signed-in organisation. Asset, document and output lookups are tenant-scoped, and the Stripe billing tables are additionally protected by database row-level security.
Passwords need at least 10 characters and are stored only as salted PBKDF2-SHA256 hashes. Browser sessions use signed, HTTP-only, secure, same-site cookies that end after at most 8 hours, at sign-out or when the password changes. Sign-in, registration and password-reset requests are rate-limited. Multi-factor authentication can be required for configured accounts.
PV8 is served only over HTTPS with automatically renewed certificates and HTTP Strict Transport Security. Pages carry a Content-Security-Policy with a fresh nonce for every response, plus anti-framing, content-type and referrer protections.
Frozen-report and collaborative-run links expose one owner-approved record and last seven days unless the owner chooses between 1 and 365 days; the owner can revoke them at any time. Viewing needs no account and a link has no password, so anyone holding an unexpired link can view that record. Changing, recalculating or commenting requires a one-time verified e-mail scoped to that record; retaining or expanding the work requires an account. The owner’s Asset Profile and other engines remain outside the link.
Uploaded evidence, accepted assumptions and expert submissions are not pooled into cross-customer benchmarks.
Uploads pass type and safety checks: executables, unsafe archives and files named as PDFs that are not PDFs are refused, and each asset has file-count and size limits. Sensitive operations are recorded in a tamper-evident audit journal, and failed erasure operations fail closed rather than reporting an incomplete deletion as successful.
Web-server access logs leave out cookies and credentials, mask the secret part of share, invitation and verification links, and are rolled daily and deleted after 28 days. Product events record signed-in users by a pseudonymised reference instead of their e-mail address. The database is backed up nightly, and off-site copies are encrypted before they leave the server.
PV8 Concierge is the optional AI-assist layer: its agents read documents and deterministic screen output and return proposals with citations. They never calculate, never change an asset, and never send a message or make a commitment without owner confirmation. AI actions are started only by signed-in users with access to the asset; a link holder’s download uses stored or cached translations and never triggers a new AI call. An organisation can have AI processing switched off for every AI provider. The Privacy Notice lists which provider receives what.
Data lifecycle
PV8 retains workspace records while the account is active and as needed for legitimate operational, contractual and legal purposes. Owners can remove assets and revoke external access, and can export their data or delete their account in account settings; the Privacy Notice explains what deletion removes and how long backups are kept. Frozen outputs and reports identify their asset, run and evidence state so recipients can distinguish current work from an older snapshot.
Responsible disclosure
Please send a concise description, affected URL or feature, reproduction steps and impact to the security contact. Do not access another customer’s data, disrupt the service or publish sensitive details before we have had a reasonable opportunity to investigate.
Sator Energy EOOD (Сейтор Енерджи ЕООД), a single-member limited liability company registered in Bulgaria, UIC/ЕИК 202053205, VAT BG202053205, 15 Aleko Konstantinov St., Poduyane, 1505 Sofia, Bulgaria. Contact: +420 771 242 881, pv8@pv8.ai.
Send security reports and privacy requests to this address.