Security and control

State the boundary. Enforce the authority. Preserve the evidence.

Security claims should describe controls that exist today, the environment they protect, and the gates that remain before customer production use.

Public demonstrations

Safe to explore; separate from customer operations.

Browser-local data

The no-login Recover, Collect, Resolve, and Community Task Marketplace demos use synthetic records in the visitor's browser. They reset on reload or on request, and demo actions do not write customer data to Civaren's product API.

Authenticated service

Customer-facing API paths are separate and require authentication. Production data and integrations remain gated by contracting, security, privacy, and operating review.

Public website

The contact and newsletter surfaces are not approved for PHI, card data, credentials, consumer credit data, or confidential production records.

Product boundaries

Different products carry different risks.

Recover: identifiable health information and live patient outreach require appropriate agreements, eligible services, access controls, procedures, and documented review.

Collect and Resolve: proofs exclude consumer or medical debt, money movement, autonomous regulated decisions, and unrestricted production data.

Community Task Marketplace: public participation and payment remain gated pending identity, safety, moderation, fraud, refund, accessibility, support, insurance, and legal controls.

Security or procurement question?

Ask for current architecture, control, data-flow, or deployment details. Do not submit sensitive production information through the public website.

Contact Civaren