Skip to content

Trust & data protection

Security built into how DIVRR works.

How DIVRR protects company policies, procedures and employee training records — described as the product works today, including what is not available yet.

Tenant isolation

Every application table has row-level security in the database. Each organization's documents, people and training records are isolated from every other organization, and server routes check access again.

Access control

Owner, Manager and Employee roles are read fresh from the database on every request. Billing, invoices, the organization data export and the audit export are restricted to the Owner.

Location scope

Managers see the people at the locations the Owner assigns them, plus people not yet placed at a location. A new location is granted to no one until the Owner assigns it.

Documents and files

Uploaded documents live in private storage reached through short-lived signed links. A document is organization-wide or targeted to locations, and that scope also applies to Ask Divrr's answers.

Payments

Subscriptions use Stripe's hosted checkout and customer portal. Card data is entered on Stripe and never reaches DIVRR.

AI handling

OpenAI receives document text to build training and, for Ask Divrr, the question plus only the excerpts that person may see. Your private content is not used to train shared or public models.

Audit log and exports

Sensitive changes are recorded in an audit log users cannot write to. Owners can export it as CSV, and request a full organization data export.

Sign-in and invitations

Membership is by invitation only. Invitation tokens are stored as hashes, expire, and can only be accepted by the confirmed email address they were sent to.

Not available yet

We say this plainly so nothing suggests otherwise:

  • Single sign-on (SSO / SAML / OIDC) or SCIM provisioning
  • Multi-factor authentication
  • SOC 2, ISO 27001, HIPAA, PCI or any other certification or attestation
  • A third-party penetration test report
  • A choice of data region per customer, or customer-managed encryption keys

Vendors that process your data are listed in our Privacy Policy.

Security questions?

We're happy to walk through how data is handled, or answer a security questionnaire.

Email support@divrr.com