Security
Provenance is designed so that the owner organization remains in control of its lease record. Security is built into the data model, not added on top.
Authentication
Sign-in is email and password, handled by a managed authentication service. Sessions use signed tokens that expire and refresh automatically, and passwords are never stored by Provenance itself.
Role-based access control
Every workspace has owners, admins, and members. Members can be scoped to specific properties, and access is enforced at the database level by Row Level Security policies.
Row Level Security
Database queries are filtered by organization membership. A user can only read or modify data that belongs to organizations they are a member of.
Append-only audit log
Fact verification, amendments, invites, and role changes are written to an append-only audit log with the actor, timestamp, and before/after values. Superseded values are retained rather than deleted.
Revocable collaborator access
Brokers, counsel, and managers are invited as guests scoped to specific properties. Invite links expire, and access can be withdrawn at any time without affecting the owner's record.
Owner-set retention policy
Each organization sets how long uploaded source documents are kept after a lease ends, and how long data survives account closure before removal. Verified facts and the audit history are append-only and are never deleted while the account is open. Every change to these windows is written to the audit log with the actor and the before/after values.
Periodic access reviews
Owners and admins can run a recorded review of everyone who holds access — members, property-scoped guests, and pending invitations — with each person's role, scope, and last recorded activity. Removals are applied as part of filing the review, and every completed review is kept permanently.
Private document storage
Uploaded lease documents are stored in a private bucket and are never publicly accessible. Access is verified on every request.
Encryption
Traffic is served over TLS, and data at rest is encrypted by the underlying cloud infrastructure provider. This is a property of the hosting platform rather than a control Provenance implements itself.
Organization-wide two-step verification
Owners and admins can require two-step verification (authenticator app) for everyone in the organization. This org-wide enforcement is optional and set per-organization; where it is off, two-step verification remains available for each user to turn on individually.
AI document processing
Uploaded documents are sent to a third-party model provider to propose structured facts. Under the provider terms in place, that content is not used to train their models. Extraction is only ever a proposal — a person verifies it before it enters the record.
Subprocessors
These are the third parties that process customer data on our behalf. The list is maintained by Provenance and was last reviewed on 23 August 2026. If you need advance notice of changes to this list, ask and we will add you to the notification list.
Managed Postgres, authentication and object storage
Stores the lease record, the audit history, and uploaded source documents. Handles sign-in and session tokens.
Data processed: Account details, lease facts, obligations, audit entries, uploaded documents
Google (Gemini models)
Reads uploaded documents and proposes structured lease terms with page citations. Proposals are never trusted until a person verifies them.
Data processed: Document content submitted for extraction
Resend
Delivers transactional email — deadline reminders, invitations, receipts and account notices — from notify.provenance.holdings.
Data processed: Recipient name and email address, message content
Paddle
Merchant of record for all subscriptions. Handles checkout, tax, invoicing and refunds. Provenance never sees or stores card details.
Data processed: Billing contact, subscription and payment status
Cloudflare
Serves the application and its API at the edge, and terminates TLS.
Data processed: Request metadata (IP address, user agent) in transit
Calendly
Books introduction and onboarding calls from the public site. Not used inside the application.
Data processed: Name, email and meeting time for people who book a call
SOC 2 readiness
Provenance does not hold a SOC 2 report and is not certified or audited against any framework. This is a self-assessed readiness checklist so a buyer can see exactly where we stand before asking.
- In place
Logical access control enforced in the database
Row Level Security on every tenant table, verified by an automated scan.
- In place
Role separation and least privilege
Owner, admin and property-scoped member roles held in a separate table; no role data on the user profile.
- In place
Append-only audit trail of changes to the record
Enforced by database trigger; verified values cannot be silently overwritten.
- In place
Encryption in transit and at rest
TLS in transit; at-rest encryption provided by the hosting platform.
- In place
Secrets management
Credentials held in the platform secret store, never in source control, and rotated on demand.
- In place
Automated vulnerability and dependency scanning
Dependency and security scans run against the codebase, with findings tracked to closure.
- Partial
Change management with recorded review
All changes are version-controlled and reviewed; the review step is not yet a documented, evidenced procedure.
- Partial
Job and delivery monitoring
Every scheduled job records its outcome and is visible in-product; alerting on a missed run is manual today.
- In place
Periodic access review
Owners can run and permanently file a recorded review of everyone holding access.
- Not started
Documented backup and recovery testing
Backups are taken by the hosting platform. We have not yet run and documented a restore test.
- Partial
Multi-factor authentication and SSO
Two-step verification with an authenticator app (TOTP) is available to every user, and owners/admins can require it organization-wide. Enterprise SSO (SAML/SCIM) is not yet available.
- Not started
Formal incident response plan
Reports are handled by the founder directly; there is no written, rehearsed plan yet.
- Not started
Independent SOC 2 Type II audit
No audit has been commissioned and no report exists. We will say so plainly until one does.
Operational transparency
The parts of Provenance that run without a person watching — deadline reminders, trial notices and follow-ups — each record whether they ran and whether they succeeded. Every customer can see this: the Alerts page in the application shows the last run of each scheduled job, flags any failure, and marks a job overdue if it stops running. We would rather you find out from the product than from us.
We do not publish an uptime figure or offer an availability guarantee, because we have not been running long enough for either to mean anything. When we have a measured history worth quoting, we will quote it.
What “permanent” means, exactly
Provenance keeps a permanent record inside your workspace: while your account exists, a verified fact is never silently altered or destroyed. Corrections and amendments append new versions and the prior value stays readable. That is a promise about how the product behaves, not a promise that we hold your data forever against your wishes.
Export. At any time you can export your register as CSV and your obligations, citations and history as PDF. Documents you uploaded can be downloaded back. Export does not require a support request or an active paid plan during the export window.
Deletion. After cancellation your workspace stays readable for 30 days so you can export. Delete it yourself at any point during that window and the data is removed from live systems within 7 days. Otherwise we delete it after the 30-day window. Encrypted backups age out within a further 35 days. We keep only what tax and dispute-resolution law requires, which is billing records — not your lease documents or facts.
These same periods appear in our Terms and Privacy Notice. If those three pages ever disagree, treat the shortest retention as correct and tell us.
Not yet available
We would rather be exact than impressive. The following are on the roadmap and are not in place today:
- Single sign-on (SAML/SCIM)
- A completed SOC 2 report
- A tested backup-and-restore procedure with a recorded restore drill
- A written, rehearsed incident-response plan
- Independent tenant-isolation testing by a third party
- A named security owner published by role and contact
- A stated hosting region commitment
Reporting a security issue
If you discover a security vulnerability, please report it to security@provenance.holdings. We take reports seriously and will respond promptly.