Skip to content

Security

Security controls implemented in the portal.

A precise view of the safeguards built into the current Everest Nova application.

Private file storage

Client uploads and deliverables are stored in non-public Supabase buckets with project-aware database and storage policies.

Account-level project access

A client account can access projects it owns. Users with the Everest Nova administrator role can access projects to operate the dossier service.

Time-limited downloads

Download requests are authorized by the application and return a signed storage link that expires after 10 minutes.

Payment separation

Stripe processes payment-card data. Everest Nova stores order status and Stripe references, not raw card numbers.

Selected activity logging

Selected account, project, file, message, checkout, order, and administrative actions are written to application logs when the production integration is configured.

Upload restrictions

The private upload bucket restricts files to configured document and image formats and applies a 100 MB per-file limit.

Current operational boundary: multi-factor authentication is not yet enforced by this application, and automated retention deletion is not enabled. Both require a controlled production rollout before Everest Nova handles higher-sensitivity work at scale.
Sensitive-data boundary: Do not upload patient, clinical-trial subject, or other directly identifiable health information. De-identify document contents and file names before upload. Report accidental disclosure or a suspected security incident promptly to security@everestnova.ai.