TRUST CENTER
Security
How SeatVara approaches account, application, and company-information security.
Updated September 20, 2026
Security approach
SeatVara uses layered administrative, technical, and organizational controls appropriate to the service’s current stage. Security is an ongoing program, not a guarantee that incidents can never occur.
Identity and access
- Verified email authentication and optional password access.
- A separate user-chosen sleep PIN for local screen locking.
- Organization-scoped authorization and explicit authority rules.
- Least-privilege access for service operations and administrative work.
Data protection
- Encryption in transit using HTTPS/TLS.
- Managed provider encryption at rest for hosted application data.
- Environment separation for production, preview, and testing.
- Secrets stored outside source code and access limited by role.
Product safeguards
- Acknowledging or dismissing a notice does not resolve its underlying issue.
- Accepted risk remains time-bounded and retains its reason and review date.
- Temporary coverage never inherits approval or spending authority.
- DecisionRoom resolution remains restricted by the related approval rule.
- External changes require an authorized connection and the applicable confirmation.
Monitoring, recovery, and response
We use provider and application logs to investigate operational and security events, maintain recovery procedures appropriate to the service, and review suspected incidents. If an incident creates a legally reportable risk, we will notify affected parties as required.
Report a security issue
Send a detailed report to legal@seatvara.ai with “Security Report” in the subject line. Do not access, modify, or retain other users’ data, disrupt the service, or use social engineering. We will acknowledge good-faith reports and coordinate next steps.