Authorisation is checked server-side against the signed-in organisation. Asset, document and output lookups are tenant-scoped.
Passwords are salted and one-way hashed. Browser sessions use signed, HTTP-only, secure cookies. Multi-factor authentication can be required for configured accounts.
Frozen-report and collaborative-run links expose one owner-approved record and default to seven days unless the owner chooses otherwise. Viewing needs no account. Changing, recalculating or commenting requires a one-time verified e-mail scoped to that record; retaining or expanding the work requires an account. The owner’s Asset Profile and other modules remain outside the link.
Uploaded evidence, accepted assumptions and expert submissions are not pooled into cross-customer benchmarks.
Uploads pass type and safety checks. Sensitive operations are audited, and failed erasure operations fail closed rather than reporting an incomplete deletion as successful.
PV8 Concierge is the optional AI-assist layer: its agents read documents and deterministic screen output and return proposals with citations. They never calculate, never change an asset, and never send a message or make a commitment without owner confirmation. AI access follows workspace permissions and is not enabled merely by holding a subscription.
Data lifecycle
PV8 retains workspace records while the account is active and as needed for legitimate operational, contractual and legal purposes. Owners can remove assets and revoke external access. Frozen outputs and reports identify their asset, run and evidence state so recipients can distinguish current work from an older snapshot.
Responsible disclosure
Please send a concise description, affected URL or feature, reproduction steps and impact to the security contact. Do not access another customer’s data, disrupt the service or publish sensitive details before we have had a reasonable opportunity to investigate.