SECURITY AND DATA HANDLING

Public data in. Drafts out. A person approves.

Ontevo reads what your market already sees and never asks for a login. What the scan produces is yours, encrypted, and never used to train a model. Nothing is published, sent or changed until someone at your company says yes. This page states what is true today, with the date on it.

Security questions: privacy@ontevo.ai. A person replies, usually the same day and always inside one business day.

Last updated: 15 September 2026.

THE DATA

What a scan reads, and what it never touches.

The scan is outside-in. It reads what your market can already see, and it never asks you for a key to anything.

01

What it reads.

Your public pages and your competitors' public pages. Google and Apple Maps listings. Marketplace pages, spec sheets and posted prices. Reviews on Google, Amazon and Trustpilot. Search rankings, backlinks and the ads running in the Meta and Google ad libraries. Page speed. And what AI assistants answer when a buyer asks about your category. All of it is already visible to your customers.

02

What it never collects.

No logins. No passwords. No connection to your CRM, your point of sale or your practice management system. No patient records: the Services do not accept protected health information, and submitting it is prohibited by Section 6.1 of our Terms. Nothing to upload, nothing to install.

03

Where it sits.

Scan outputs are processed and stored in the United States, encrypted in transit (TLS 1.3) and at rest (AES-256). We maintain separate data environments for each customer. Your business intelligence is never commingled with another customer's data.

04

What we hold, and for how long.

What the scan produces, and the account and billing details you give us. Never used to train models, never sold, never shared. It is a term in our Terms of Service, on every plan. The retention schedule for each kind of record is in Section 6 of the Privacy Policy.

Benchmarks come from public market records, never from another customer's data.

CONTROLS

What is in place today.

Each line below is a practice, not a certificate. Every one of them is true right now, and none of them needs an auditor to be true.

01

Data.

  • Your data is encrypted in transit (TLS 1.3) and at rest (AES-256), processed and stored in the United States, and held in a separate environment from every other customer's.

  • Payment card numbers are never stored on our servers: billing is handled by Stripe, which maintains PCI DSS Level 1 compliance, and our cloud infrastructure providers maintain ISO 27001 certification.

02

Access.

  • Access to customer data is role-based and limited to authorized personnel, and sign-in is handled by a dedicated identity provider rather than one we built.

03

Product.

  • The product reads public data only, with no logins, no integrations and nothing to upload, and every external write is drafted and held for a person at your company to approve.

04

Commitments in writing.

  • Your data is never used to train models, never sold and never shared. That is a term in our Terms of Service, on every plan, and the Terms also prohibit sending us protected health information.

  • Breach notice: no later than 72 hours after we confirm an incident.

THE APPROVAL QUEUE

Agents draft. A person approves before anything goes live.

The Evo Agents write the review reply, the listing update, the follow-up email. Each one lands in an approval queue as a draft. Someone at your company opens it, reads it, and approves it or does not. Only then does it leave our system. This is not a permission level or a default we set for you: there is no configuration that lets an agent publish on its own, and there is no plan on which that changes.

That matters for a security review for one reason. The blast radius of a mistake on our side is a draft nobody approved. It is not a post on your Google Business Profile, an email to your list, or a change to your website.

COMPLIANCE STATUS

Where we are, and where we are not.

SOC 2 Type I and HIPAA readiness are in progress. We do not currently hold a SOC 2 report, and we will not say we do until the report is in hand.

Ontevo does not currently offer a HIPAA Business Associate Agreement. The product is outside-in on public signals and does not accept protected health information, so a covered entity using Ontevo is not disclosing PHI to us. If your compliance team needs that in writing for their file, write to privacy@ontevo.ai and we will put it in a letter.

We publish no framework logos and no compliance badges, because we do not hold the reports that would sit behind them. When that changes, it will appear in the updates below with a date on it.

UPDATES

15 SEPTEMBER 2026

This page published, with the controls, the documents we send to a security reviewer and the current compliance status in one place.

4 AUGUST 2026

Privacy Policy and Terms of Service published, with the no-training commitment written into the Terms as a contractual term.

ON REQUEST

What we send a security reviewer.

Write to privacy@ontevo.ai with your company name and what your process needs. A person replies, usually the same day and always inside one business day.

Data processing agreement.

A data processing agreement is available on request for portfolio and enterprise customers. It covers the standard processor terms, including breach notice, deletion and audit rights.

Security questionnaires.

We complete vendor security questionnaires, including CAIQ-style ones. Send yours and we will return it filled in, with the unanswered rows marked as unanswered rather than guessed.

Sub-processors.

A current description of the third-party service providers material to your account is available on request at privacy@ontevo.ai. It names the vendor, what it does, and what it touches.

FAQ

The questions a security review actually asks.

Do you have SOC 2?

No. SOC 2 Type I and HIPAA readiness are in progress. We do not currently hold a SOC 2 report. We will not claim one until the report is in hand.

Will you sign a BAA?

No. Ontevo does not currently offer a HIPAA Business Associate Agreement. The scan is outside-in on public signals, with no logins and no access to a practice management system, and the Terms prohibit submitting protected health information. If your compliance file needs a vendor statement saying we neither receive nor store PHI, ask and we will send one.

What data of ours do you actually hold?

What the scan produces about your business and your competitors, all of it built from public sources, plus the account and billing details you give us when you sign up. No credentials, no customer records, no files from your systems.

Where is it stored, and is it encrypted?

Scan outputs are processed and stored in the United States. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). We maintain separate data environments for each customer.

Do you train models on our data?

Never. Your competitive intelligence stays yours. It is a term in our Terms of Service, on every plan, and it applies on the third-party model services we use to deliver analysis.

Can an agent post or send something without us?

No. Every external write is drafted and held for approval. A person at your company reads each draft and approves it or does not. There is no setting that turns this off and no plan on which it works differently.

What happens if you have a breach?

Ontevo will notify affected customers without undue delay and no later than 72 hours after we confirm an incident involving customer data, with a plain-language description of what happened, what data was involved, and what the customer should do. The clock starts at confirmation, not at occurrence.

Who do you use to run the product?

Billing is handled by Stripe, which maintains PCI DSS Level 1 compliance. Our platform runs on enterprise cloud infrastructure whose providers maintain ISO 27001 certification. Certain analysis features are delivered using third-party AI model services, and our no-training commitment applies there too. A current description of the third-party service providers material to your account is available on request at privacy@ontevo.ai.

NEXT

Bring us your security review.

If your process needs a questionnaire filled in, a DPA signed or a call with the person who built the system, book fifteen minutes. If you would rather see the product first, the Rapid Scan needs your website and your email and nothing else.

FREE RAPID SCAN

Find an opportunity your business could act on.