Tenant-aware access
Workspace-scoped data access and reviewer workflows are treated as core product constraints.
Security and privacy
CVault separates controls available now, deployment-specific commitments, and claims that are not made without evidence.
What is protected now, what depends on customer setup, and what is not claimed?
workspace scope
audit events
retention terms
deployment review
DPA review
security notes
The public security page is deliberately precise: no fake badges, no broad compliance guarantees.
Workspace-scoped data access and reviewer workflows are treated as core product constraints.
Pilot data is handled with explicit lifecycle expectations before broader rollout.
Security and privacy copy separates available controls from contract-scoped commitments.
Claim registry
Each statement carries an internal evidence ID and a status so buyers can see what is available versus scoped.
Evidence ID: privacy-dpa-retention-controls. Category: privacy.
Evidence ID: dpa-page-and-vendor-review. Category: privacy.
Evidence ID: model-use-policy. Category: privacy.
Evidence ID: data-retention-policy. Category: privacy.
Evidence ID: enterprise-roadmap-and-contract-review. Category: security.
Evidence ID: workspace-security-controls. Category: security.
Evidence ID: enterprise-contract-review. Category: operations.
Evidence ID: parser-language-routing. Category: parser.
Evidence ID: integration-copy-review. Category: integration.
Reviewed rollout
Use a scoped pilot to confirm data handling, retention, and reviewer access expectations.