Your leases, your mail,
your business. Kept that way.
You are handing Sevrel the paperwork your company runs on. This page says, in plain words, how that information is kept apart from everyone else’s, what the software will not do without your say-so, and where we are still working. The technical version for your IT person is linked at the bottom.
Only your company can see your company's files.
Every company on Sevrel has its own workspace. The separation is built into the database itself, not just the screens, and each time we change the software an automatic test tries to read one company’s records from another and has to fail before the change can go out.
Your files are never in the same pile as another owner’s.
Sensitive numbers are blacked out before the AI reads anything.
Social Security numbers, bank account and routing numbers, card numbers, dates of birth, licence and passport numbers, and personal payroll or financial amounts are replaced with a black bar before a document is indexed or sent to an AI model. This is always on. There is no setting that turns it off, and if the step ever fails the document is held back rather than sent.
Names, tenant and landlord details, and business contact information stay readable, because a lease is useless without them. A company’s own tax ID can be blacked out too if you ask for the stricter setting.
The AI works from the redacted copy, never the original numbers.
In exact terms: document text passes through a deterministic redaction engine, and each detected identifier is replaced with a typed [REDACTED_*] token before it is chunked, embedded, or sent to any AI model. The engine fails closed. Always redacted: Social Security, ITIN and taxpayer numbers; bank account and routing numbers; IBANs; card numbers; dates of birth; licence and passport numbers; payroll and personal financial amounts. Redacted in personal or guarantor context: personal email, phone and home address. Business EIN redaction is a per-organization strict mode. Not redacted: person, tenant and landlord names, and business contact details.
Nothing goes out without your say-so.
Sevrel can draft an email to a tenant or a vendor and put a repair visit on the calendar. It cannot send or book them on its own. Each one waits for a person on your team to look at it and confirm, and that confirmation is tied to that person and that action, so it cannot be reused.
It stays a draft until someone on your team says send.
You decide who on your team can do what.
People sign in with their Microsoft account, with an optional code from their phone, and there are no Sevrel passwords to leak. You choose who can only look, who can work, and who can change settings, and you can write your own roles if those three do not fit. Those limits are checked on every request, not just hidden in the menu.
When someone leaves, an admin can sign them out of every device at once.
Access follows your org chart, and ends when you say so.
There is a record of who did what.
Sign-ins and failed sign-ins, role changes, questions asked and the documents used to answer them, and every time a document is added or opened are written to a log. Entries can be added but not edited or deleted; the database itself refuses. Your admins can read your company’s log inside Sevrel.
If a question ever comes up, the answer is written down.
Your documents are not used to teach the AI.
Sevrel does not use your content to train its own models. The AI provider we use, Anthropic, does not use API data to train its models either. Under their standard commercial terms, what is sent is kept for up to 30 days for abuse monitoring and then discarded, longer only if something is flagged for review. Anthropic’s “Zero Data Retention” option is not yet in place for Sevrel, and we will not say it is until we have that in writing.
Where we are still working.
A security page that only lists the good news is not one you should trust. These are the things we would want to know if we were you.
We are not SOC 2 audited yet.
The readiness work is under way. Until an outside auditor signs off, we say so.
The AI can be wrong.
Answers point to the document they came from so you can check. Read the source before you act on a date or a dollar figure.
Nobody is on call overnight yet.
Errors are detected and reported automatically. A person reads security reports, but we do not yet promise a response time.
Some settings live with our hosting providers.
Encryption of stored data and network settings are provided by Cloudflare and Railway. Your IT person can ask us for the current evidence.
For your IT person, or for a closer look.
The full technical statement of each control, and the documents your reviewer will ask for.
- Technical security statementIdentity, encryption, tenant isolation, hardening and monitoring, control by control.
- Privacy PolicyWhat is collected, kept and deleted.
- Data Processing AddendumThe contract terms for handling your data.
- Sub-processor registerEvery outside company that touches your data, and why.
Found a security problem?
Email [email protected] with what you found and how to reproduce it. A person reads every report and replies on a best-effort basis; we do not yet publish a formal response time or a legal safe-harbour statement, and where a customer agreement sets security-contact obligations, that agreement governs.
In scope: sevrel.com, www.sevrel.com and api.sevrel.com. Out of scope: our vendors’ own systems, customer-controlled document storage and mail tenants, and any testing that would touch another company’s data. Please do not run automated scanners or load generators against production.