Skip to main content
Porvio
ProductWorkflowArticlesPricingSecurity
Sign inCreate workspace →
Menu
ProductWorkflowArticlesPricingSecurity
Sign inCreate workspace

Trust and safety

Security

Implemented safeguards, shared responsibilities, and a private path for responsible vulnerability reporting.

UpdatedAugust 16, 2026

Document revision2026-08-16

Ask a question

On this page

  1. 01Security approach
  2. 02Controls implemented in Porvio
  3. 03Infrastructure and provider controls
  4. 04Security assurances and scope
  5. 05Protect your workspace
  6. 06Report a vulnerability privately
  7. 07Research boundaries
  8. 08Suspected privacy or account incident
Back to top ↑
Sections8
  1. 01Security approach
  2. 02Controls implemented in Porvio
  3. 03Infrastructure and provider controls
  4. 04Security assurances and scope
  5. 05Protect your workspace
  6. 06Report a vulnerability privately
  7. 07Research boundaries
  8. 08Suspected privacy or account incident

Clinical-use responsibilities

Porvio supports clinician-controlled documentation workflows that may involve patient information. Each organization and user must use the Service only within their lawful authority, approved role, professional scope, and permitted jurisdiction. The organization remains responsible for completing required privacy, security, and clinical-risk reviews; giving required notices and obtaining legally valid consent before recording; limiting information to the approved purpose; configuring access and retention; reviewing every AI-generated clinical output; and maintaining a non-AI documentation alternative.

If Porvio, applicable law, or the organization’s governance requires a written clinic or data-processing agreement, that agreement must be in effect before the covered processing begins. These public documents do not replace the clinic’s patient notice, consent process, privacy assessment, policies, or professional and legal duties.

01Security approach

Porvio uses layered technical and workflow controls to reduce the risk of unauthorized access, unsafe files, cross-organization disclosure, and unreviewed AI content. Security is shared: Porvio protects the Service, organizations manage their people and records, and every user must protect their account and device.

Scope reviewed August 16, 2026: repository-controlled application safeguards described below. This is not an independent assessment of a deployed Cloudflare account, vendor contract, clinic configuration, or operational response program.

02Controls implemented in Porvio

  • Account creation requires email verification and password reset uses a short-lived email code. Email two-factor authentication is required for support administration and for every active member accessing a production clinical workspace. Porvio rechecks the verified initiating session at direct-file, realtime, AI-provider, and AI-commit boundaries.
  • Public backend functions resolve the signed-in identity and check active organization membership and role server-side.
  • Clinical workspace access expires after 15 minutes without a trusted foreground interaction. A two-minute accessible warning permits an explicit renewal; background network activity cannot renew the server-owned deadline, and session-scoped tab signals coordinate warning and logout. The interval is a risk-based Porvio control, not a claim that Ontario law sets one universal number.
  • Screen privacy update (August 16, 2026). A user who has set a four-digit screen PIN can hide the clinical workspace immediately, and Porvio also hides it after five minutes without a trusted foreground interaction. The PIN reopens only that already authenticated session. Five incorrect entries revoke that session. If no screen PIN is set, Porvio signs the user out at the five-minute privacy boundary. The PIN does not replace the password, email two-factor authentication, device lock, or fresh email verification for protected actions. For current screen-lock mechanics, this dated implementation note replaces the email-code-only description in Terms section 4 and Privacy Notice section 10.
  • Clinical records are organization-scoped, and file identifiers are not treated as authorization.
  • The current patient-AI notice, decision source, method, and express consent attestation must be recorded before audio upload or AI processing begins; a later withdrawal retires source audio and stops queued or running work.
  • Audio uploads require an authenticated, short-lived claim; enforce the approved origin; inspect the file signature; and enforce a 25 MiB and 90-minute maximum.
  • Upload and AI workflows have rate, concurrency, state-transition, and retry boundaries.
  • Model credentials and deployment keys remain server-side rather than in the browser bundle.
  • Audit events record actor, time, action, resource, and result without intentionally duplicating full clinical content.
  • A workspace owner’s structured data copy requires a fresh, one-use email code for both preparation and download. The private file expires after 72 hours and excludes credentials, binary source files, support attachments, and private teammate direct-message content.
  • Generated content is validated, displayed as a draft, and separated from clinician approval.

03Infrastructure and provider controls

Connections use encrypted transport. Porvio keeps service credentials out of the browser, stores structured data and files in private managed services, and authorizes each application and file request. Cloudflare publishes its current platform controls through its Trust Hub.

Those are provider-reported controls. They do not make Porvio end-to-end encrypted, prove Canadian residency, or automatically satisfy a clinic’s legal obligations. Vendor contracts and production configuration remain part of security review.

04Security assurances and scope

No product control or provider assurance makes an organization automatically compliant with PHIPA, PIPEDA, HIPAA, or another law. Compliance depends on the organization’s role and use, configuration, contracts, policies, training, notices, consent, and documented risk assessment. Porvio does not claim a SOC 2 attestation, ISO certification, HIPAA certification, or similar independent assurance unless a current written statement expressly says so.

Organizations must confirm that Porvio’s retention, export, deletion, backup, incident-response, support-access, and offboarding capabilities meet their requirements before placing patient information in the Service.

05Protect your workspace

  • Use a unique password and protect the email account tied to Porvio.
  • Do not share accounts, passwords, invitation links, or browser sessions.
  • Keep devices, browsers, and operating systems current and encrypted.
  • Sign out of shared devices and remove access promptly during offboarding.
  • Grant only the minimum role required for each person.
  • Never send patient data, secrets, or access tokens through ordinary support email.

06Report a vulnerability privately

Email support@porvio.app with the subject “Private security report” and ask for a secure reporting channel. In that first message, include only your contact details and a brief, non-sensitive description. Do not put exploit details, credentials, patient information, or clinical records in a public issue or ordinary email.

Porvio aims to acknowledge a private report within five business days. An acknowledgment is not a promise that investigation or remediation will finish within that period. Porvio does not authorize testing outside the boundaries below.

When safe, include:

  • the affected route, component, commit, or deployment;
  • reproduction steps that avoid patient data and use only your own account;
  • the likely impact and required preconditions;
  • screenshots or logs with tokens and personal information removed; and
  • a safe way to contact you.

07Research boundaries

During security research, do not access, copy, change, or retain patient data. Do not perform denial-of-service testing, social engineering, physical attacks, credential stuffing, automated destructive testing, or testing against an account you do not own. Stop immediately if personal information becomes visible and report only the minimum needed to find the exposure. Coordinated disclosure timing will depend on severity, exploitation risk, and remediation readiness.

08Suspected privacy or account incident

If you suspect unauthorized access, sign out where possible, secure the affected email account and device, preserve relevant evidence without copying clinical content, and contact support@porvio.app. Send privacy concerns to support@porvio.app. Do not delay emergency or patient-safety action while waiting for Porvio support.

The responsible Ontario health information custodian must run its PHIPA breach process, including notice to affected individuals at the first reasonable opportunity where required, notice to the IPC in prescribed circumstances, and annual breach-statistics reporting. Porvio’s role, cooperation, and notice timing must also be set in the applicable written agreement and incident plan.

Return to top ↑
Porvio

The work around care,finally connected.

Clinical documentation that keeps consent, review, and the final decision with the clinician.

Built for eligible Ontario healthcare organizations.
ExploreProductWorkflowArticlesPricing
TrustSecurityPrivacyResponsible AIPatient AI noticeAccessibility
AccountPorvio.appSign inCreate workspaceEmail support

© 2026 Porvio

TermsCookies & storage