Skip to content

Security and data

You share sensitive information with us. This is how we handle it.

Anyone providing evidence about someone else's security should show how they work themselves. Here it is, no small print.

Version 1.1 · updated 8 October 2026

Before you share anything

NDAWe sign your NDA or ours before any confidential material is shared.
Data processing agreementFor documents in an engagement we sign a data processing agreement, listing the parties that process your data.
Rules of EngagementFor AI tests we agree in writing up front: which environment, which time window, who the contact is and how to stop a test.
Forms on the siteThe website only asks for contact details and a short note. We ask for questionnaires and confidential documents only after the NDA, through the secure transfer method agreed for the engagement.

Where your data is stored

Website and formsNetlify (US). Only what you fill in on a form. Transfers outside the EU are based on the standard contractual clauses in Netlify's data processing agreement.
Domain nameCloudflare manages the DNS for holdvero.com.
EmailMicrosoft 365 (Microsoft Ireland Operations Ltd.).
Confidential engagement documentsOnly shared after an NDA, through the secure transfer and storage method agreed for the engagement. The relevant processors and locations are recorded in the data processing agreement before any processing. Not as email attachments.
Statistics and trackingVisitor counts via Cloudflare Web Analytics, without cookies. Fonts served from our own server. No advertising cookies or advertising tracking.

AI and your documents

Your documents are not used to train AI models. If we use an AI service in an engagement, for example to find evidence in your documents, it will only be a provider that contractually does not use your data for training. That provider is listed in the data processing agreement up front. Without your agreement we don't use it.

Every answer and finding is checked by a person and points to a source you can verify.

What we remove and what we keep

Source files and extracted source content are removed from our active systems within 90 days after the engagement ends, unless otherwise agreed in writing.

Evidence excerpts relied upon in issued reports, issued reports themselves, and necessary audit records are retained to preserve assurance and auditability.

How we test AI

Only with permissionWritten authorisation up front. Without signed Rules of Engagement we test nothing.
Never in productionOnly in a test or staging environment you designate, with fictional data.
Within limitsWithin a fixed time window, without actions that change anything, with a stop procedure.
Repeated and recordedEvery scenario several times, with run IDs, so your buyer can see exactly what was tested.

Access

WhoOnly those working on your engagement. At the moment that is the founder.
AccountsThe Holdvero environment is administered with a separate admin account, not the everyday one.

Honest about where we are

Holdvero is a young company. We don't (yet) have an ISO 27001 certificate or a SOC 2 report. We will only use our own evidence and testing platform for confidential customer documents once it has passed our production tests. Until then we work with the arrangements and services on this page.

Report a vulnerability

Found a security issue on our website or in our services? Email security@holdvero.com. We respond within 2 working days. See also our security.txt file.

Privacy questions are covered in the privacy notice.