Security and data handling at EvaCore
Security at EvaCore is a set of controls that exist in the product today: 2-step sign-in with an authenticator app, roles that confine each employee to their own pages, an audit history the owner can read, and rate limiting on sign-in attempts. The full truth about hosting is that production runs on us-central1 and AI processing happens outside the Kingdom.
This page states only what exists in the product, and we read every item in the code before writing it. We do not list compliance certificates we do not hold, and we do not describe hosting we do not provide. If your organisation needs something not mentioned here, ask us before you subscribe and we will answer with what actually exists.
Protection starts at sign-in: passwords are stored as bcrypt hashes, never as plain text, the session cookie cannot be read by page scripts, and in production it travels only over an encrypted connection. Sign-in attempts, password resets and verification codes are all rate-limited per minute or per hour so guessing cannot go on forever.
Then come permissions: the owner manages billing, integrations, settings and members, a member sees what belongs to their work, a call-center account reaches follow-up pages only, and finance reaches reservations, deposits, buyer payments and developer figures without conversations or leads. Anything not explicitly listed for a call-center or finance account is refused to it by default.
Finally transparency: the audit history tells the owner who changed a price, a lead's owner, a permission or a setting, and when. Details that look like secrets, such as passwords and keys, are masked before anything is displayed.
2-step sign-in
After the password the system asks for a six-digit code from an authenticator app, which changes every 30 seconds. When you turn it on you receive 10 recovery codes shown once, and each is used up after it is spent. The office owner can require 2-step sign-in of every member, and when that is switched on the sessions of anyone who has not enabled it are ended. A member who has not enrolled yet sets it up on the sign-in page itself. The verification step lasts five minutes and works once, and code attempts are rate-limited.
Roles and permissions
Every account has one of four roles: owner, member, call-center and finance. Billing, integrations, office settings and member management are limited to the owner. Call-center and finance accounts are blocked from every page not listed for them, so typing another address into the browser does not get either of them there. In offices that have teams, a team lead sees their team's leads.
Audit history
The change history shows the owner who did what and when, with an Arabic description for every action. It can be filtered by category, such as leads, projects and prices, reservations, team and permissions, and settings, and exported to a CSV file. It is for the owner alone, and the system checks that before reading a single row. It belongs to the team tools in the Agency plan.
Session and password protection
Passwords are stored as bcrypt hashes. The session cookie is protected from page scripts, travels over an encrypted connection in production, and expires. The platform rate-limits sign-in attempts, password resets and verification-code entries.
Uploaded files
When you upload an image or a PDF, the file name and the type the browser reports are not trusted. The system inspects the file's own content, accepts only PDF, JPEG, PNG, WebP and GIF, and limits the size in pixels of accepted images.
The hosting truth
Production runs today on us-central1, a region in the United States. AI processing happens outside the Kingdom. We do not say your data sits in Saudi Arabia because that is not true today. In-Kingdom hosting is available on request on a Saudi cloud, by quote for each customer, and the AI model stays outside the Kingdom even then.
What we do not claim
We do not claim a compliance certificate for any named standard, and we do not claim that the platform is approved by any particular body. We describe only what exists in the product, and if your organisation needs a specific document, ask us and we will say plainly what we have and what we do not.
Frequently asked questions
- How do I turn on 2-step sign-in?
- You turn it on from your account page with any authenticator app that generates six-digit codes. When you do, 10 recovery codes are shown once, so save them. If you want your whole team to use it, require it from the team settings.
- What if I lose the phone that holds my authenticator app?
- You can sign in with one of the ten recovery codes you received when you turned it on, and each code is used up once spent. Keep them somewhere safe, away from your phone.
- Who can read the audit history?
- Only the owner can read the audit history, and the system checks the role before reading a single row. Members, call-center staff and finance do not see that page.
- Is our data kept inside Saudi Arabia?
- No, production runs on us-central1 today, and AI processing happens outside the Kingdom. In-Kingdom hosting is available on request by quote, and the AI model itself stays outside the Kingdom.
- Can an employee see data that is not part of their work?
- No, each role has its own pages. Call-center and finance accounts are refused by default anything not listed for them: a call-center account reaches follow-up pages and a few basic pages only, finance reaches reservations, deposits, buyer payments and developer figures only, and a member sees what belongs to their work.
- Do you hold compliance certificates?
- We do not cite a compliance certificate because we do not claim anything that does not exist. If you need a document or an answer to a specific security question for your organisation, write to us and we will answer with what actually exists.
Ready to try it on your office?
Create your workspace and start, or talk to us if you have a larger project.