SECURITY AT RECOVA
Clear controls. Clear limits.
Recova is operated by Dmitry Rossi LLC. This page describes controls implemented in the product; it is not an independent audit or certification.
Account access and business separation
Sign-in uses Auth0. Server-side sessions, active organization membership and role checks control access to customer records. PostgreSQL row-level security adds a database boundary between businesses. The website uses HTTPS.
Evidence and review
Recovery and commission ledgers preserve an append-only record of events. Payment evidence, independent commission review and reversal handling are separate from sales-stage labels. Access to a workspace does not automatically authorize a payment or a message.
Integrations and credentials
Provider credentials are handled on the server. Demo records are synthetic and kept separate from customer workspaces. CRM and messaging capabilities require the appropriate business authorization and channel setup before use.
Security review status
Recova has internal automated checks. An independent third-party penetration test or security assessment has not been completed for this release. We do not claim SOC 2 or ISO 27001 certification.
Report a concern
Use the contact form and select Security. Include the affected page, what happened and how we can reach you. Do not submit passwords, API keys, card details or another customer’s private records.
For information about personal data, see our Privacy Policy.