Trust

Can you put your company's data on Ofivio?

Every question a software security review asks, answered on one page, with a link to the document that is the authority for each answer. Where the answer is uncomfortable, it is here too — and first.

OFIVIO (SMC-PRIVATE) LIMITED · Lahore, Pakistan · policies last updated 9 September 2026

What we do not have

The things a large buyer will look for and not find, 3 of them. We would rather you read them here than discover them in month three.

  • Do you hold SOC 2 or ISO 27001?No. We do not hold an independent SOC 2 or ISO 27001 audit of our own. The Google Cloud infrastructure we build on carries SOC 1, 2 and 3 and ISO 27001 — those are Google's certifications, not ours, and we will not present them as ours. This page changes the day that changes.Security, section 3
  • Is there a status page?There is a live one: it checks the API, the application and this site from your own browser, right now, and prints the build the API is running. What it does NOT publish is a historical uptime percentage, because we do not yet run the third-party monitoring that would make that figure honest — and we sell no uptime SLA outside an Enterprise agreement.Status
  • A published customer list.Ofivio is young and we do not yet publish named customers or case studies. The honest proof we can offer is a demo on your own project, and a free workspace you can test with data you choose.Book a demo →

The review

The whole checklist, answered

Every row cites the policy that governs it. If a fact changes, it changes there and this link takes you to it.

Who are we contracting with?

In place

OFIVIO (SMC-PRIVATE) LIMITED, a single-member private company registered in Pakistan, with its office in Lahore. The same entity is named on every policy.

Terms, section 1

Do you hold SOC 2 or ISO 27001?

Not yet

No. We do not hold an independent SOC 2 or ISO 27001 audit of our own. The Google Cloud infrastructure we build on carries SOC 1, 2 and 3 and ISO 27001 — those are Google's certifications, not ours, and we will not present them as ours. This page changes the day that changes.

Security, section 3

Where is our data held?

In place

Google Cloud Platform, us-central1 (Iowa, United States). VO's language-model and speech providers process requests in the United States and Europe. If you are outside those places, the transfer relies on the providers' standard contractual clauses.

Privacy, section 7

Is it encrypted?

In place

TLS in transit, AES-256 at rest, including uploaded files. Standard hardening headers on every response.

Security, section 3

How is our workspace kept separate from another company's?

In place

Every workspace has its own identifier, and every read and write is scoped to the identifier in your signed session token. The scoping is enforced on the server and again by database rules — not by hiding things in the interface. A request for another organisation's record fails at the source.

Security, section 1

Is there two-factor authentication?

In place

On by default, on every account. Every sign-in — password or Google — is completed with a one-time code, so a password alone never opens an account. Anyone can also enrol an authenticator app (Google Authenticator or any TOTP app) from their own settings and take their codes off the phone instead of the inbox; the shared secret is sealed with AES-256-GCM under a key that never leaves the server. Email is never removed, so a lost phone is a nuisance rather than a lock-out. Enterprise SSO — SAML 2.0, OAuth 2.0, OpenID Connect — is available on agreement. A hardware key or passkey is not yet offered.

Security, section 2

Can we lock the rooms that hold the money?

In place

Yes, and it is separate from roles. The Workspace owner can lock any dashboard: a person who holds the role still holds it and still cannot open the room until the owner generates a code and hands it over. It is the control for payroll, the ledger and partner-level figures — grant somebody the role they need to work, and keep the room that holds the money shut until you decide otherwise.

Security, section 5

Does your AI train on our data?

In place

No, and it is contractual. VO sends only what is needed to answer a request — your question and the records your own role may read — and our agreements forbid the providers from using it for model training. VO cannot exceed your permissions: what a role cannot see, VO cannot retrieve, summarise or act on. Voice audio is not retained.

AI and your data

Who else touches our data?

In place

Every subprocessor is listed with what it does and what it receives: Google Cloud for hosting, Anthropic, OpenAI and DeepSeek for VO's language models, ElevenLabs for speech, Google reCAPTCHA for abuse control, and Google Analytics on the public pages only — never on workspace data.

Subprocessors

Who owns the data, and can we get it out?

In place

You do. Reports export to CSV and PDF, and a full workspace export in JSON/CSV can be requested at any time — during a subscription, during a trial, and throughout the 90 days a lapsed workspace is kept. We do not sell it or advertise against it.

Terms, section 8

What happens when we leave?

In place

A cancelled or unpaid workspace is suspended, not deleted: the data is kept for 90 days, exportable throughout, and restored exactly as it was if you come back inside that window. After 90 days it is permanently deleted, and it ages out of backups as they cycle.

Privacy, section 10

Is there an audit trail?

In place

Actions inside a workspace are written to an immutable trail — who acted, on what, when, and what changed. It cannot be edited or deleted from the application, including by an administrator.

Security, section 7

Can we control who sees what?

In place

Roles are enforced on the server, not hidden in the interface. An assignment is private to the people on it; internal margins, vendor rates and payroll are invisible to the roles that should not hold them, and the client portal is read-only and shows only what you share.

Security, section 1

Is there a status page?

With a limit

There is a live one: it checks the API, the application and this site from your own browser, right now, and prints the build the API is running. What it does NOT publish is a historical uptime percentage, because we do not yet run the third-party monitoring that would make that figure honest — and we sell no uptime SLA outside an Enterprise agreement.

Status

Is there a DPA?

In place

Yes — a standard Data Processing Agreement is published and forms part of the Terms for every customer, with nothing to sign before you can rely on it: the controller/processor split, processing on documented instructions, confidentiality, the security measures, subprocessors and how they change, help with data-subject requests, breach notification, deletion and return, and international transfers. A counter-signed copy on your own paper is available for an Enterprise agreement.

Data Processing Agreement

How do we report a vulnerability?

In place

Write to contact@ofivio.com with the subject line "Security", or read the machine-readable contact at /.well-known/security.txt. We aim to acknowledge within two business days and to keep you updated until it is resolved. We will not pursue a researcher who reports in good faith.

Security, section 10

The honest way to evaluate this

Do not decide from a marketing page — ours included. Open a free workspace and put one real project through it end to end: a bill of quantities into a purchase order, into the store, onto the site, into an invoice, into the ledger. That will tell you more in an afternoon than any document on this site.

Security questions before you start: contact@ofivio.com