Security
Last updated: 2026-09-13
This page summarizes the technical and organizational measures Grovic Data applies to protect the Valerium platform, and what our customers are responsible for on their side. It is informational: the contractual allocation of responsibilities is set out in the Terms of Service, and personal data handling in the Privacy Policy.
Each organization is logically separated. Access to tenant data is enforced by authorization checks in the API and, for data read with the user's own session, by Row-Level Security policies in the database, so a single faulty check is not meant to be enough to expose another organization's data.
Sensitive operations, such as financial and destructive actions, are recorded in an audit log. Application errors are monitored and alerted on, and access logs are kept for at least 6 months as required by Brazilian law.
Changes go through automated checks, including security-focused tests for sensitive endpoints, and periodic security reviews. Issues rated high or critical are prioritized for remediation before release.
We investigate security events, contain and remediate confirmed incidents, and notify affected customers as described in the Terms of Service and the Privacy Policy. We may suspend an account immediately when that is necessary to contain a threat.
If you believe you have found a vulnerability, email support@grovicdata.com with enough detail to reproduce it. We will not pursue legal action against good-faith research that avoids privacy violations, data destruction and service degradation, does not access or retain data beyond what is needed to demonstrate the issue, and gives us reasonable time to fix it before any disclosure. We do not operate a paid bug bounty program.
No system is completely secure. The measures described here are reviewed and may change over time, and this page is not a warranty or a contractual commitment beyond what the Terms of Service provide.
Security: support@grovicdata.com · Privacy: dpo@grovicdata.com.