Security and ownership

This page describes what Plenvera does today, and what is still being verified before paid launch. It is not a certification.

  • Separation between organizations

    Every organization’s content is checked in the application, and the database enforces the same boundary on its own with row-level security, so an application mistake does not expose another organization’s data. Automated tests try to cross that boundary on every change.

  • Access and roles

    People see only the organizations they belong to, with the role they were given. Drafts are visible to the team only; previews use private links that expire.

  • Hosting

    Production is planned in Canadian regions of our hosting providers. Before launch we will publish what each provider confirms for each environment. Some services, such as email delivery, may process data elsewhere; we will list them.

  • Updates

    The platform is updated centrally. Changes are tested automatically before release, and releases can be rolled back.

  • Backups

    Backup and restore procedures are being prepared and tested. Their schedule and retention will be published here before paid launch.

  • Your content

    Your content belongs to your organization. Owners can export it at any time, and cancelling never deletes it on the spot.

Not yet done

  • An independent security review
  • Verification of hosting regions in production
  • Published backup and recovery targets
  • Reviewed privacy notice and terms

A simpler next step for your organization’s website.

Explore a template, see how editing works, and choose the setup that fits your team.