This page is maintained by the Jorvea team to answer common security and privacy questions about the Service. It describes controls that are enabled today. It is not a certification or an independent audit.
Infrastructure
- Hosted on managed cloud infrastructure with global edge delivery and DDoS protection from the underlying platform.
- Production data is isolated from development environments.
Encryption
- TLS in transit for all traffic between your browser and Jorvea.
- Managed database encryption at rest, provided by our database vendor.
- User-supplied auto-apply credentials are encrypted at the application layer with AES-256-GCM before being written to the database; decryption happens only server-side during an application run.
- Secrets and API keys are stored in the platform's managed secret store, not in source code.
Access control
- Row-Level Security is enforced on customer-data tables so a signed-in account can only read and write its own rows.
- Role-based access for the small team with access to production; least-privilege by default.
- Multi-factor authentication is required for team accounts that can reach production.
Application security
- Server-side input validation with Zod on all authenticated endpoints; parameterized queries only.
- Modern security headers served by the hosting platform.
- Automated dependency scanning; vulnerable packages are updated on a rolling basis.
Automation transparency
- Jorvea supports three automation modes: Manual and Assisted are approval-first (nothing external is sent without your explicit approval). Auto mode, which you must explicitly enable, submits applications and sends outreach automatically within the rules you set (match threshold, daily caps, blocked companies), with a one-tap pause/kill-switch.
- AI providers are used under contracts that do not permit training on your data.
- Auto-apply activity is logged so you can review what was submitted on your behalf.
- You remain responsible for the content submitted in your name.
Business continuity
- Managed daily backups and point-in-time recovery are provided by our database vendor.
Compliance
- Jorvea is not currently SOC 2, ISO 27001, or HIPAA certified. If you need a specific attestation, contact us before purchasing.
- We design toward GDPR / UK GDPR principles. A Data Processing Addendum can be discussed with business customers on request.
Responsible disclosure
Found a vulnerability? Please email contact@ealimitless.com with a clear description and reproduction steps. Please do not access data that isn't yours, disrupt the Service, or exfiltrate data while researching.
