Classified:Institutional Grade.
Zurvek processes pitch decks, financial models, cap tables, and business plans — documents containing unpublished financial data and proprietary business strategies. This is not consumer software. The security architecture reflects that.
Data Architecture
Zero Retention by Default: Documents are processed in ephemeral containers. The original document is not retained beyond the processing window unless explicitly saved.
Where Your Data Is Processed: Application data and documents are stored in our managed cloud database and storage in the European Union (Ireland region), encrypted with AES-256 at rest. Analysis runs through the Zurvek Engine gateway over TLS 1.3 in transit. No document data is used to train models. This is a statement of our current practice, maintained by VentureSense Technologies LLP — it is not a certification or an audit result.
Regulatory Posture: VentureSense Technologies LLP operates as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023. Cross-border transfers are made on the basis set out in our Privacy Policy, with a published grievance route.
Encryption Standards
| Layer | Standard |
|---|---|
| Data in transit | TLS 1.3 |
| Data at rest | AES-256 |
| Authentication tokens | JWT with RS256 |
| Session management | Rotating tokens, server-side invalidation |
| Password storage | bcrypt with adaptive cost factor |
Access Controls
- All evaluation data behind authentication. No public access.
- Role-based access for Syndicate and Institutional tiers.
- Sessions expire after inactivity. Concurrent limits by tier.
- Internal staff access logged, audited, and limited to essential personnel.
Third-Party Sub-processors
| Provider | Data |
|---|---|
| Lovable Cloud (Supabase) | User accounts, evaluation metadata, encrypted outputs |
| Lovable AI Gateway (Gemini) | Document excerpts during processing window only |
| Razorpay / Paddle | Payment data only — never touches evaluation data |
| Mailgun | Email address, transactional notification content |
| Cloudflare | Edge routing, DNS, DDoS mitigation |
Vulnerability Disclosure
Contact: support@zurvek.com · PGP key available on request.
- • Acknowledged within 48 hours
- • No legal action against good-faith researchers
- • Credit provided with permission
- • Critical vulnerabilities remediated within 72 hours
What We Do Not Do
- • We do not sell user data to any third party
- • We do not allow model providers to train on your raw documents
- • We do not share evaluation outputs with any party other than the authenticated account holder
- • We do not store payment card data
- • We do not claim SOC 2, ISO 27001, or PCI certification — where controls above map to a framework, they are described factually, not certified
Anonymized signals used for benchmark corpora are governed by the Privacy Policy §3; opt out via support@zurvek.com.
Last updated: 15 August 2026 · VentureSense Technologies LLP · LLPIN: ACR-5230 · support@zurvek.com

