Security

How we handle the most sensitive data a business has: its email.

Architecture

OVIOO is an application talking to our backend and, for mail itself, to your provider. Business logic that must not be tampered with — permissions, entitlements, billing state, audit logging — lives on the server, never only in the client.

Every record belongs to an organisation, and that boundary is enforced in queries on the server rather than by filtering in the interface.

Credentials and connections

  • OAuth is preferred for Microsoft 365 and Google; tokens are encrypted at rest and never returned to the client.
  • IMAP/SMTP passwords are encrypted at rest and are never displayed again after saving.
  • Traffic is encrypted in transit. The local cache on the desktop machine is encrypted and separated per organisation.
  • Sessions are per device and can be revoked individually.

Access follows roles

  • Mailbox access is assigned per person by the owner — not every user sees every inbox.
  • Company file sources are connected once at organisation level; the connected account defines the maximum OVIOO can ever access, and the owner grants scopes inside it per user, department or role.
  • Ask OVIOO, search and attachment suggestions run inside the permissions of the person asking. There is no broader "search everything" path.

The AI boundary

Authorisation is resolved before anything is retrieved for a model — not by sending everything and instructing the model to be discreet. If a person cannot open a mailbox or a file scope, its content cannot reach an AI answer that person receives.

The organisation owner controls which AI capabilities are enabled at all. Individual users may be stricter than that policy; nobody can be looser.

Automatically created relationships that matter — an email linked to a reference, a document routed by a rule — record how they were made. Where confidence is insufficient, OVIOO proposes and a person confirms.

Our access to your mail

By default, nobody at OVIOO can read your message content. Support access must be granted by you, is scoped to what is needed, expires automatically, names the person who received it and is written to your audit log.

Deletion and retention

Removing a mailbox or ending a subscription starts a 30-day retention window with a visible deletion date, an export and a cancel button. We do not destroy business data because of a UI mistake or a failed sync.

Reporting a vulnerability

Write to security@ovioo.app with steps to reproduce. We will acknowledge within three business days, keep you updated, and credit you if you would like that. Please do not test against other customers’ data, and give us reasonable time before publishing.

Certifications

We do not currently hold [SOC 2 / ISO 27001] certification and we are not going to print a badge we have not earned. Ask where we are in the process and you will get the honest state of it. GDPR, for the avoidance of doubt, is not a certification anyone can hold.

See it on your own mailbox

Fourteen-day trial for the whole organisation, no card.