Security

Provenance is designed so that the owner organization remains in control of its lease record. Security is built into the data model, not added on top.

Authentication

Sign-in is email and password, handled by a managed authentication service. Sessions use signed tokens that expire and refresh automatically, and passwords are never stored by Provenance itself.

Role-based access control

Every workspace has owners, admins, and members. Members can be scoped to specific properties, and access is enforced at the database level by Row Level Security policies.

Row Level Security

Database queries are filtered by organization membership. A user can only read or modify data that belongs to organizations they are a member of.

Append-only audit log

Fact verification, amendments, invites, and role changes are written to an append-only audit log with the actor, timestamp, and before/after values. Superseded values are retained rather than deleted.

Revocable collaborator access

Brokers, counsel, and managers are invited as guests scoped to specific properties. Invite links expire, and access can be withdrawn at any time without affecting the owner's record.

Owner-set retention policy

Each organization sets how long uploaded source documents are kept after a lease ends, and how long data survives account closure before removal. Verified facts and the audit history are append-only and are never deleted while the account is open. Every change to these windows is written to the audit log with the actor and the before/after values.

Periodic access reviews

Owners and admins can run a recorded review of everyone who holds access — members, property-scoped guests, and pending invitations — with each person's role, scope, and last recorded activity. Removals are applied as part of filing the review, and every completed review is kept permanently.

Private document storage

Uploaded lease documents are stored in a private bucket and are never publicly accessible. Access is verified on every request.

Encryption

Traffic is served over TLS, and data at rest is encrypted by the underlying cloud infrastructure provider. This is a property of the hosting platform rather than a control Provenance implements itself.

Organization-wide two-step verification

Owners and admins can require two-step verification (authenticator app) for everyone in the organization. This org-wide enforcement is optional and set per-organization; where it is off, two-step verification remains available for each user to turn on individually.

AI document processing

Uploaded documents are sent to a third-party model provider to propose structured facts. Under the provider terms in place, that content is not used to train their models. Extraction is only ever a proposal — a person verifies it before it enters the record.

Subprocessors

These are the third parties that process customer data on our behalf. The list is maintained by Provenance and was last reviewed on 23 August 2026. If you need advance notice of changes to this list, ask and we will add you to the notification list.

Managed Postgres, authentication and object storage

Stores the lease record, the audit history, and uploaded source documents. Handles sign-in and session tokens.

Data processed: Account details, lease facts, obligations, audit entries, uploaded documents

Google (Gemini models)

Reads uploaded documents and proposes structured lease terms with page citations. Proposals are never trusted until a person verifies them.

Data processed: Document content submitted for extraction

Resend

Delivers transactional email — deadline reminders, invitations, receipts and account notices — from notify.provenance.holdings.

Data processed: Recipient name and email address, message content

Paddle

Merchant of record for all subscriptions. Handles checkout, tax, invoicing and refunds. Provenance never sees or stores card details.

Data processed: Billing contact, subscription and payment status

Cloudflare

Serves the application and its API at the edge, and terminates TLS.

Data processed: Request metadata (IP address, user agent) in transit

Calendly

Books introduction and onboarding calls from the public site. Not used inside the application.

Data processed: Name, email and meeting time for people who book a call

SOC 2 readiness

Provenance does not hold a SOC 2 report and is not certified or audited against any framework. This is a self-assessed readiness checklist so a buyer can see exactly where we stand before asking.

  • Logical access control enforced in the database

    Row Level Security on every tenant table, verified by an automated scan.

    In place
  • Role separation and least privilege

    Owner, admin and property-scoped member roles held in a separate table; no role data on the user profile.

    In place
  • Append-only audit trail of changes to the record

    Enforced by database trigger; verified values cannot be silently overwritten.

    In place
  • Encryption in transit and at rest

    TLS in transit; at-rest encryption provided by the hosting platform.

    In place
  • Secrets management

    Credentials held in the platform secret store, never in source control, and rotated on demand.

    In place
  • Automated vulnerability and dependency scanning

    Dependency and security scans run against the codebase, with findings tracked to closure.

    In place
  • Change management with recorded review

    All changes are version-controlled and reviewed; the review step is not yet a documented, evidenced procedure.

    Partial
  • Job and delivery monitoring

    Every scheduled job records its outcome and is visible in-product; alerting on a missed run is manual today.

    Partial
  • Periodic access review

    Owners can run and permanently file a recorded review of everyone holding access.

    In place
  • Documented backup and recovery testing

    Backups are taken by the hosting platform. We have not yet run and documented a restore test.

    Not started
  • Multi-factor authentication and SSO

    Two-step verification with an authenticator app (TOTP) is available to every user, and owners/admins can require it organization-wide. Enterprise SSO (SAML/SCIM) is not yet available.

    Partial
  • Formal incident response plan

    Reports are handled by the founder directly; there is no written, rehearsed plan yet.

    Not started
  • Independent SOC 2 Type II audit

    No audit has been commissioned and no report exists. We will say so plainly until one does.

    Not started

Operational transparency

The parts of Provenance that run without a person watching — deadline reminders, trial notices and follow-ups — each record whether they ran and whether they succeeded. Every customer can see this: the Alerts page in the application shows the last run of each scheduled job, flags any failure, and marks a job overdue if it stops running. We would rather you find out from the product than from us.

We do not publish an uptime figure or offer an availability guarantee, because we have not been running long enough for either to mean anything. When we have a measured history worth quoting, we will quote it.

What “permanent” means, exactly

Provenance keeps a permanent record inside your workspace: while your account exists, a verified fact is never silently altered or destroyed. Corrections and amendments append new versions and the prior value stays readable. That is a promise about how the product behaves, not a promise that we hold your data forever against your wishes.

Export. At any time you can export your register as CSV and your obligations, citations and history as PDF. Documents you uploaded can be downloaded back. Export does not require a support request or an active paid plan during the export window.

Deletion. After cancellation your workspace stays readable for 30 days so you can export. Delete it yourself at any point during that window and the data is removed from live systems within 7 days. Otherwise we delete it after the 30-day window. Encrypted backups age out within a further 35 days. We keep only what tax and dispute-resolution law requires, which is billing records — not your lease documents or facts.

These same periods appear in our Terms and Privacy Notice. If those three pages ever disagree, treat the shortest retention as correct and tell us.

Not yet available

We would rather be exact than impressive. The following are on the roadmap and are not in place today:

  • Single sign-on (SAML/SCIM)
  • A completed SOC 2 report
  • A tested backup-and-restore procedure with a recorded restore drill
  • A written, rehearsed incident-response plan
  • Independent tenant-isolation testing by a third party
  • A named security owner published by role and contact
  • A stated hosting region commitment

Reporting a security issue

If you discover a security vulnerability, please report it to security@provenance.holdings. We take reports seriously and will respond promptly.