Request demo
TRUST CENTER

Security at Orva OS

Practical safeguards, clear boundaries, and a responsible way to report concerns.

Last updated August 4, 2026

Our approach

Restoration operations depend on reliable, trustworthy information. Orva OS builds security into product and website decisions from the start and evolves safeguards as the platform and customer needs grow. This page describes our current public posture and is not a certification or contractual warranty.

Website and form protection

Website traffic is protected in transit using HTTPS when served from our production domain. Public forms are sent to Formspree over encrypted connections and are intended only for business contact information—not claim files, credentials, payment information, health information, or other sensitive records.

  • Bot-resistant honeypot fields help reduce automated form abuse.
  • Website analytics are anonymous, exclude IP addresses, demographic data, and form field values, and are never used for advertising.
  • Dependencies, static generation, linting, type checking, and governed design-token checks are validated before release.

Secure development practices

We use source control, peer-review-ready changes, automated quality checks, least-privilege configuration, and separated public configuration values. Secrets should not be committed to source control, and production access is limited to people and services that need it.

Service providers

We select infrastructure and service providers based on their role, security capabilities, and fit for the information they process. Providers receive only the access reasonably needed to perform their services, and their own published security and privacy terms also apply.

Product and customer data

Security commitments for customer accounts, product data, retention, availability, incident handling, and integrations will be documented in the applicable customer or beta agreement. Prospective customers can request current security information during evaluation.

Report a security concern

If you believe you found a vulnerability affecting an Orva OS website or product, email support@orvaos.com with “Security report” in the subject line. Include the affected URL or feature, steps to reproduce, potential impact, and a safe way to contact you. Please avoid accessing, changing, downloading, or publicly disclosing data that is not yours while investigating.

What to expect

We will acknowledge a credible report, investigate it, and coordinate next steps as appropriate. Response and remediation timing depends on severity, complexity, and the affected systems. We appreciate good-faith reports that protect customers and the broader restoration community.