Security
Last updated: June 24, 2026
This page summarizes the safeguards Covision uses to protect customer workspaces, integration connections, OAuth tokens, and financial records.
1. Security contact
Report security concerns to [email protected]. We acknowledge security disclosures within 24 hours and triage confirmed issues under our incident response process.
Please include a clear description of the issue, affected URL or account context, reproduction steps, and any relevant screenshots or logs. Do not access, modify, delete, or exfiltrate customer data while testing.
2. Data protection controls
- Encryption in transit: customer traffic and integration callbacks use HTTPS/TLS.
- Encryption at rest: application data is stored in managed infrastructure with encryption at rest.
- Token protection: OAuth access and refresh tokens are encrypted before persistence.
- Secret handling: server-side secrets stay in backend environment variables and are not exposed through browser bundles.
- Least privilege: integrations request the scopes required for enabled product workflows.
- Auditability: sync status, connection state, and operational logs are retained for support and incident review.
3. Financial and integration data
Covision connects to services such as Ramp, Plaid, QuickBooks, Stripe, and Google Calendar only after an authorized user completes the provider's OAuth or connection flow. Integration data is used to power customer-requested dashboards, cash-flow views, accounting workflows, and operational reporting.
Covision does not sell customer data and does not use customer business data or integration data to train AI models. Access is scoped by workspace, organization membership, and application permissions.
4. Access control
- Users authenticate before accessing private application data.
- Role-based access control limits administrative, financial, and support workflows.
- Customer financial data is scoped to the connected workspace or organization.
- Employee access is limited to personnel who need it for support, operations, security, or compliance work.
5. Monitoring and incident response
Covision uses application monitoring, error reporting, and operational logs to detect failures and investigate security events. Confirmed incidents are assigned a severity level, contained, investigated, remediated, and documented. Where legally required, affected customers and regulators are notified without undue delay.
6. Retention and deletion
Account and business data is retained while an account remains active. After account closure, data is retained for 30 days and then deleted, except where legal, tax, accounting, or security obligations require retention. Financial records may be retained for up to 7 years. See our Privacy Policy andData Deletion page for details.
When a customer disconnects an integration, Covision stops using the revoked connection. Stored integration records can be deleted on request unless retention is required for legal, accounting, or security reasons.
7. Security review materials
Security questionnaires, vendor review responses, and additional compliance materials are available to customers, partners, and integration reviewers on request. Contact[email protected] for review coordination.