Sign-in
E-mail and password hashed with Argon2id, account lockout after repeated failures, and optional two-factor codes (TOTP). Single sign-on with OIDC and SAML is planned.
Project data is commercial data. Here is what protects it today, and what is planned, without the fine print.
E-mail and password hashed with Argon2id, account lockout after repeated failures, and optional two-factor codes (TOTP). Single sign-on with OIDC and SAML is planned.
HttpOnly, SameSite cookies and sessions that expire. A device list with remote sign-out is planned.
Workspace roles (owner, PMO, PM, member, viewer) and project membership decide what each person can see and change.
Every record carries its workspace, and every query is filtered by it. PostgreSQL row-level security is planned as a second line of defence.
Every change is recorded with who made it and what changed, and most changes can be undone.
TLS in transit. Encryption at rest and field-level encryption of secrets are part of the production design.
The production design keeps daily backups with point-in-time recovery for 35 days, in the same region, with a monthly restore drill.
Uploaded files are size-limited and parsed with safe parsers before anything reaches your data.
Critova is cloud-hosted on a portable stack, encrypted in transit and at rest. The production regions are being set up; ask us for their current status before you plan a rollout.
Send it to us with your procurement timeline and we will answer it.
Contact usThis page is not legal advice. Compliance positions are confirmed with counsel in your jurisdiction before contracts are signed.