What this document is, and is not
Not settled / not in placeCovio holds no security certification. It is not ISO 27001 certified, has no SOC 2 report, has had no independent penetration test, and holds no certification under any privacy law. Everything below is a control Covio operates and can show you in its own code and configuration. None of it is an attestation by anybody else.
1 · Separating one company from another
- Every query the platform makes is scoped to the company of the signed-in person. Tenant isolation is the platform's first rule and nothing is exempt from it.
- Identity comes from a server-side session and only from there. No endpoint accepts a company, an email address or a role supplied by the browser, and adding a second way to establish identity is forbidden.
- Every table holding company data carries a company identifier with an index, so isolation is a property of the schema and not only of the code that reads it.
- Requesting something that belongs to another company returns a not-found, not a permission error — so a probe cannot learn that a thing exists.
2 · Signing in
| Control | As configured |
|---|---|
| Password storage | Argon2id. The password itself is never stored and cannot be recovered — a reset issues a new one |
| Password length | At least 12 characters, set on the invitation screen |
| Sessions | Stored in the database, not in a self-describing token. Seven days by default; thirty with "keep me signed in", in which case the ceiling is thirty days; refreshed on activity at most once a day. Without "keep me signed in" the cookie dies when the browser closes |
| Second step | Required for owners, administrators, partner administrators and Covio operators. A six-digit code to WhatsApp, valid five minutes. Seven days' grace from first sign-in, counted down in a banner, after which the account cannot be used until it is set up |
| Recovery codes | Shown once, each usable a single time |
| Rate limiting | Stored in the database so it survives a restart and applies across instances. 100 requests per minute per IP across authentication routes; 10 per minute for sign-in; 3 per 15 minutes for a password reset request; a tighter budget still on requesting a WhatsApp code |
| Lockout | Repeated failures pause sign-in for that identifier |
| Reset links | Valid 24 hours, usable once |
3 · The network edge
- One container is exposed to the internet: the Caddy edge, on ports 80 and 443. Nothing else publishes a port.
- Neither database publishes a port. Postgres and MySQL are reachable only from inside the container network.
- Certificates are obtained and renewed automatically. TLS 1.2 is the minimum and TLS 1.3 is used where the client supports it; plain HTTP is redirected to HTTPS; HTTP/3 is available.
- HTTP Strict Transport Security is set for one year including subdomains.
- The edge removes the Server header, and strips request headers, TLS details and response headers out of its access log rather than recording them.
4 · Documents and files
- No document is ever served as a static file. Every read goes through an authenticated route that checks the session and the company, and writes a row to the access ledger before it returns any bytes — so the ledger cannot be missing for a download that happened.
- The ledger records who, which file, which action, whether it was allowed, and why it was refused when it was not.
- Uploads are validated and scanned before they are stored.
- Each file carries a SHA-256, which is what lets a customer prove a file they download later is the file Covio held.
- A withdrawn document is not a deleted document, deliberately: the record of what was once relied on survives until the company itself is purged.
5 · Records that cannot be rewritten
Seven ledgers are append-only, and the enforcement is a database trigger rather than a coding convention: an update or a delete is refused by the database itself. They are the platform action ledger, the machine measurement ledger, the approval decision history, machine calibration, the WhatsApp consent record, the wire run ledger, and the record of every panel validation check.
The one exception is a purge, which must first declare inside the transaction which single company it is destroying. A mistaken condition therefore raises an error rather than taking another customer's history with it.
6 · Covio Connect reads, and only reads
Covio Connect never writes to a customer's TallyPrime books, and this is enforced twice. The job table accepts only read-kind jobs, enforced by a database constraint. Separately, every request composed for a connector must match an allowlist of read shapes before it is sent: the validator permits a narrow named shape and refuses everything else, including Tally's import envelope and any create, alter, delete or cancel action.
The allowlist fails closed. A legitimate future read shape it does not yet know about will be refused until somebody widens it deliberately. That is the correct direction to be wrong in: the opposite failure writes to a customer's books and cannot be undone.
7 · Covio staff access
- Support access runs under a recorded grant, and every screen opened is written to an access log naming the Covio person, the panel and the resource.
- Both the grant and the log are included in the customer's export, so a customer can audit Covio rather than take its word.
- Both are deliberately retained when a company is purged, because deleting them would destroy the evidence that the access happened — which is the record a customer disputing it would need.
8 · Backups
- A full backup set runs nightly at 02:15, covering both databases and the media store.
- Every archive is encrypted with AES-256-CBC, keyed through PBKDF2 at 200,000 iterations. The key is never passed on a command line.
- The fourteen most recent sets are kept on the server.
- A backup is taken before every production deployment that applies a migration — between the build and the restart, never at container boot.
- Restores are drilled rather than assumed.
Not settled / not in placeThere is no off-host or off-site backup destination operating today. A second destination has been specified and the tooling to upload to it is written and ready, but no account, credential or bucket exists, so every backup that exists is on the same machine as the data it protects. Covio states this rather than describing a disaster-recovery capability it does not have.
9 · Encryption at rest
Not settled / not in placeBackup archives are encrypted, as described above. Covio makes no claim that the live databases or the document store are encrypted at rest on the server's disk, because it has not established that they are. A statement about disk-level encryption must come from the hosting arrangement, not from this page.
10 · Secrets and change control
- Secrets live in a file on the server with restricted permissions, never in the repository. A leaked secret is rotated the same day.
- The server receives code only through git, with a read-only deploy key. There is no other way in.
- Every change reaches production through a pull request and an automated check suite, and the deployment fails loudly unless the site then serves that exact commit.
- Schema changes are generated as migrations, committed with the feature that needs them, and applied by the deployment between the build and the restart.
What counsel must rule on before this stops being a draft
Covio drafted this document from its own systems rather than from a template, so what follows are the points where engineering cannot decide and a lawyer must.
- 1Does the absence of an off-host backup need to be disclosed to customers in the contract, and does it need to be fixed before a customer with statutory record-keeping obligations can be signed?
- 2Is a statement about disk-level encryption at rest required, and if so must Covio obtain it in writing from the hosting provider?
- 3Covio has no written confidentiality undertaking, background check or security training for the people with production access. Is any of that required before these documents can be relied on?
- 4Is any of this sufficient to answer a customer security questionnaire, or must Covio obtain an independent assessment first?
- 5What wording may Covio use to describe these controls in sales material without implying a certification it does not hold?