Security approach
Porvio uses layered technical and workflow controls to reduce the risk of unauthorized access, unsafe files, cross-organization disclosure, and unreviewed AI content. Security is shared: Porvio protects the Service, organizations manage their people and records, and every user must protect their account and device.
Scope reviewed August 16, 2026: repository-controlled application safeguards described below. This is not an independent assessment of a deployed Cloudflare account, vendor contract, clinic configuration, or operational response program.
Controls implemented in Porvio
- Account creation requires email verification and password reset uses a short-lived email code. Email two-factor authentication is required for support administration and for every active member accessing a production clinical workspace. Porvio rechecks the verified initiating session at direct-file, realtime, AI-provider, and AI-commit boundaries.
- Public backend functions resolve the signed-in identity and check active organization membership and role server-side.
- Clinical workspace access expires after 15 minutes without a trusted foreground interaction. A two-minute accessible warning permits an explicit renewal; background network activity cannot renew the server-owned deadline, and session-scoped tab signals coordinate warning and logout. The interval is a risk-based Porvio control, not a claim that Ontario law sets one universal number.
- Screen privacy update (August 16, 2026). A user who has set a four-digit screen PIN can hide the clinical workspace immediately, and Porvio also hides it after five minutes without a trusted foreground interaction. The PIN reopens only that already authenticated session. Five incorrect entries revoke that session. If no screen PIN is set, Porvio signs the user out at the five-minute privacy boundary. The PIN does not replace the password, email two-factor authentication, device lock, or fresh email verification for protected actions. For current screen-lock mechanics, this dated implementation note replaces the email-code-only description in Terms section 4 and Privacy Notice section 10.
- Clinical records are organization-scoped, and file identifiers are not treated as authorization.
- The current patient-AI notice, decision source, method, and express consent attestation must be recorded before audio upload or AI processing begins; a later withdrawal retires source audio and stops queued or running work.
- Audio uploads require an authenticated, short-lived claim; enforce the approved origin; inspect the file signature; and enforce a 25 MiB and 90-minute maximum.
- Upload and AI workflows have rate, concurrency, state-transition, and retry boundaries.
- Model credentials and deployment keys remain server-side rather than in the browser bundle.
- Audit events record actor, time, action, resource, and result without intentionally duplicating full clinical content.
- A workspace owner’s structured data copy requires a fresh, one-use email code for both preparation and download. The private file expires after 72 hours and excludes credentials, binary source files, support attachments, and private teammate direct-message content.
- Generated content is validated, displayed as a draft, and separated from clinician approval.
Infrastructure and provider controls
Connections use encrypted transport. Porvio keeps service credentials out of the browser, stores structured data and files in private managed services, and authorizes each application and file request. Cloudflare publishes its current platform controls through its Trust Hub.
Those are provider-reported controls. They do not make Porvio end-to-end encrypted, prove Canadian residency, or automatically satisfy a clinic’s legal obligations. Vendor contracts and production configuration remain part of security review.
Security assurances and scope
No product control or provider assurance makes an organization automatically compliant with PHIPA, PIPEDA, HIPAA, or another law. Compliance depends on the organization’s role and use, configuration, contracts, policies, training, notices, consent, and documented risk assessment. Porvio does not claim a SOC 2 attestation, ISO certification, HIPAA certification, or similar independent assurance unless a current written statement expressly says so.
Organizations must confirm that Porvio’s retention, export, deletion, backup, incident-response, support-access, and offboarding capabilities meet their requirements before placing patient information in the Service.
Protect your workspace
- Use a unique password and protect the email account tied to Porvio.
- Do not share accounts, passwords, invitation links, or browser sessions.
- Keep devices, browsers, and operating systems current and encrypted.
- Sign out of shared devices and remove access promptly during offboarding.
- Grant only the minimum role required for each person.
- Never send patient data, secrets, or access tokens through ordinary support email.
Report a vulnerability privately
Email support@porvio.app with the subject “Private security report” and ask for a secure reporting channel. In that first message, include only your contact details and a brief, non-sensitive description. Do not put exploit details, credentials, patient information, or clinical records in a public issue or ordinary email.
Porvio aims to acknowledge a private report within five business days. An acknowledgment is not a promise that investigation or remediation will finish within that period. Porvio does not authorize testing outside the boundaries below.
When safe, include:
- the affected route, component, commit, or deployment;
- reproduction steps that avoid patient data and use only your own account;
- the likely impact and required preconditions;
- screenshots or logs with tokens and personal information removed; and
- a safe way to contact you.
Research boundaries
During security research, do not access, copy, change, or retain patient data. Do not perform denial-of-service testing, social engineering, physical attacks, credential stuffing, automated destructive testing, or testing against an account you do not own. Stop immediately if personal information becomes visible and report only the minimum needed to find the exposure. Coordinated disclosure timing will depend on severity, exploitation risk, and remediation readiness.
Suspected privacy or account incident
If you suspect unauthorized access, sign out where possible, secure the affected email account and device, preserve relevant evidence without copying clinical content, and contact support@porvio.app. Send privacy concerns to support@porvio.app. Do not delay emergency or patient-safety action while waiting for Porvio support.
The responsible Ontario health information custodian must run its PHIPA breach process, including notice to affected individuals at the first reasonable opportunity where required, notice to the IPC in prescribed circumstances, and annual breach-statistics reporting. Porvio’s role, cooperation, and notice timing must also be set in the applicable written agreement and incident plan.