Who are we contracting with?
In placeOFIVIO (SMC-PRIVATE) LIMITED, a single-member private company registered in Pakistan, with its office in Lahore. The same entity is named on every policy.
Terms, section 1 →Trust
Every question a software security review asks, answered on one page, with a link to the document that is the authority for each answer. Where the answer is uncomfortable, it is here too — and first.
OFIVIO (SMC-PRIVATE) LIMITED · Lahore, Pakistan · policies last updated 9 September 2026
The things a large buyer will look for and not find, 3 of them. We would rather you read them here than discover them in month three.
The review
Every row cites the policy that governs it. If a fact changes, it changes there and this link takes you to it.
OFIVIO (SMC-PRIVATE) LIMITED, a single-member private company registered in Pakistan, with its office in Lahore. The same entity is named on every policy.
Terms, section 1 →No. We do not hold an independent SOC 2 or ISO 27001 audit of our own. The Google Cloud infrastructure we build on carries SOC 1, 2 and 3 and ISO 27001 — those are Google's certifications, not ours, and we will not present them as ours. This page changes the day that changes.
Security, section 3 →Google Cloud Platform, us-central1 (Iowa, United States). VO's language-model and speech providers process requests in the United States and Europe. If you are outside those places, the transfer relies on the providers' standard contractual clauses.
Privacy, section 7 →TLS in transit, AES-256 at rest, including uploaded files. Standard hardening headers on every response.
Security, section 3 →Every workspace has its own identifier, and every read and write is scoped to the identifier in your signed session token. The scoping is enforced on the server and again by database rules — not by hiding things in the interface. A request for another organisation's record fails at the source.
Security, section 1 →On by default, on every account. Every sign-in — password or Google — is completed with a one-time code, so a password alone never opens an account. Anyone can also enrol an authenticator app (Google Authenticator or any TOTP app) from their own settings and take their codes off the phone instead of the inbox; the shared secret is sealed with AES-256-GCM under a key that never leaves the server. Email is never removed, so a lost phone is a nuisance rather than a lock-out. Enterprise SSO — SAML 2.0, OAuth 2.0, OpenID Connect — is available on agreement. A hardware key or passkey is not yet offered.
Security, section 2 →Yes, and it is separate from roles. The Workspace owner can lock any dashboard: a person who holds the role still holds it and still cannot open the room until the owner generates a code and hands it over. It is the control for payroll, the ledger and partner-level figures — grant somebody the role they need to work, and keep the room that holds the money shut until you decide otherwise.
Security, section 5 →No, and it is contractual. VO sends only what is needed to answer a request — your question and the records your own role may read — and our agreements forbid the providers from using it for model training. VO cannot exceed your permissions: what a role cannot see, VO cannot retrieve, summarise or act on. Voice audio is not retained.
AI and your data →Every subprocessor is listed with what it does and what it receives: Google Cloud for hosting, Anthropic, OpenAI and DeepSeek for VO's language models, ElevenLabs for speech, Google reCAPTCHA for abuse control, and Google Analytics on the public pages only — never on workspace data.
Subprocessors →You do. Reports export to CSV and PDF, and a full workspace export in JSON/CSV can be requested at any time — during a subscription, during a trial, and throughout the 90 days a lapsed workspace is kept. We do not sell it or advertise against it.
Terms, section 8 →A cancelled or unpaid workspace is suspended, not deleted: the data is kept for 90 days, exportable throughout, and restored exactly as it was if you come back inside that window. After 90 days it is permanently deleted, and it ages out of backups as they cycle.
Privacy, section 10 →Actions inside a workspace are written to an immutable trail — who acted, on what, when, and what changed. It cannot be edited or deleted from the application, including by an administrator.
Security, section 7 →Roles are enforced on the server, not hidden in the interface. An assignment is private to the people on it; internal margins, vendor rates and payroll are invisible to the roles that should not hold them, and the client portal is read-only and shows only what you share.
Security, section 1 →There is a live one: it checks the API, the application and this site from your own browser, right now, and prints the build the API is running. What it does NOT publish is a historical uptime percentage, because we do not yet run the third-party monitoring that would make that figure honest — and we sell no uptime SLA outside an Enterprise agreement.
Status →Yes — a standard Data Processing Agreement is published and forms part of the Terms for every customer, with nothing to sign before you can rely on it: the controller/processor split, processing on documented instructions, confidentiality, the security measures, subprocessors and how they change, help with data-subject requests, breach notification, deletion and return, and international transfers. A counter-signed copy on your own paper is available for an Enterprise agreement.
Data Processing Agreement →Write to contact@ofivio.com with the subject line "Security", or read the machine-readable contact at /.well-known/security.txt. We aim to acknowledge within two business days and to keep you updated until it is resolved. We will not pursue a researcher who reports in good faith.
Security, section 10 →Do not decide from a marketing page — ours included. Open a free workspace and put one real project through it end to end: a bill of quantities into a purchase order, into the store, onto the site, into an invoice, into the ledger. That will tell you more in an afternoon than any document on this site.
Security questions before you start: contact@ofivio.com