Evora

Security

Who can reach your record, and how you would know.

This page is written to be checked, not admired. Below is what is enforced in the product today, what happens to your data from the moment it arrives until you delete it, and a plain list of what is not in place yet.

No certifications claimed · No badges · Statements only

In place today

Six things the product actually does

Each of these is enforced in code and visible to you inside your own record — not a policy we intend to follow.

  1. 01

    A record is readable only by the person it belongs to.

    Every table that holds health data is closed by default and opened one row at a time, to one account. There is no query in the product that returns another person's results, and no shared-view path that does not begin with that person granting it.

    Enforced at the database, not in the interface

  2. 02

    Sharing is scoped, purpose-stated, expiring, and logged.

    When you share, you choose which parts — results, vitals, documents, notes, what's next — say what it is for, and set an end date. The view is read-only. You can end it at any moment, and it ends on its own even if you forget.

    Live now at /sharing

  3. 03

    Every open is written down where you can read it.

    Each time someone opens part of your record, a line is added to your access history: who, when, and which part. That history is append-only — it cannot be edited or quietly cleaned up, not by them and not by us.

    Live now at /activity

  4. 04

    Traffic is encrypted, and so is storage.

    Connections use current TLS, and data at rest is encrypted by the managed database and file storage the record sits on. Uploaded reports are held in private storage that is not reachable by URL guessing.

    Managed infrastructure, not hand-rolled

  5. 05

    You can take the whole record out, at any time.

    A full machine-readable export, a results file you can open in a spreadsheet, and a printable one-page summary for a visit. No request form, no waiting period, no charge. Portability is what makes the other promises credible.

    Live now at /export

  6. 06

    Health data is never sold.

    Not sold, not brokered, not licensed, not used to build advertising profiles, and not handed to insurers or employers. Individuals never pay; organizations pay for their own tooling. That is the whole business model, stated in one sentence.

    Read the full terms on the data promise

The life of one reading

From the report in your hand to the day you delete the account

Five steps, in order. Nothing skips a step, and no step happens without you.

01

It arrives

You upload a report or enter a reading. The file is stored privately, the values are read out of it, and each value keeps a note of where it came from and how confident that read was.

02

It stays yours

The record accumulates rather than resets. Old draws are never overwritten by new ones, because the comparison between them is the point.

03

You lend a view of it

A clinician, a family member, or an organization sees only the parts you named, for only as long as you said, and their visit is recorded.

04

You correct it

A misread value can be corrected without erasing what was originally read. Both the correction and the original stay visible, so nobody has to trust a silent edit.

05

You leave with it

Export everything, then delete the account. Deletion removes the record and its files; the access history of who once looked is removed with it.

Not yet true

What we are not claiming

A security page that lists only strengths is an advertisement. These four are the honest gaps, and they will be corrected here — not quietly dropped — when they change.

We do not hold a SOC 2 report or any security certification.

No audit has been completed, and none is in progress. When that changes we will name the standard, the period covered, and who performed the work — or we will keep saying this.

EVORA is not operating under a HIPAA business-associate agreement.

The record is designed around HIPAA's basic ideas — least access, an audit trail, a person's right to their own data — but designing around a rule is not the same as being covered by it, and we will not blur those two things.

Device sync is not connected.

Oura and Whoop developer approval is still pending. Nothing in the product reads from a wearable account today, and no page says otherwise.

Email delivery is not switched on.

Reminders are prepared and shown inside your record, and each one says plainly whether it was emailed. None have been.

Reporting a problem

If you find something, tell us and we will answer

We would rather hear about a weakness than discover it later. Send what you found, how to reproduce it, and how you would like to be credited.

Please do not access, alter or download anyone else's record while testing — a description is enough. We will confirm receipt, tell you what we found, and say when it was fixed.

This page describes how EVORA is built and operated. It is not a legal agreement, a certification, or medical advice. The terms that govern the record are on the privacy and terms pages, and the commitments behind it are on the data promise.