Use accountable access
Connect important actions to named people, and avoid shared or ambiguous responsibility.
Corva One is coming soon. This page describes the principles guiding its design — not deployed controls, service levels, or independent assurance.
No certifications, audit reports, production architecture or uptime commitments are claimed here.
Specific safeguards will be published only when they can be supported with current evidence. Until then this page describes intent, and labels it as intent.
Corva One has not launched. There is no production environment, no customer data, and therefore nothing to make assurances about yet. Saying so plainly is the first security principle on this page.
When the product does open, the controls described below will be documented as shipped behaviour, with the same distinction between what exists and what is planned that the rest of this site uses.
Control that lives only in an administrator's screen is control nobody sees. These principles put it where the work happens.
Connect important actions to named people, and avoid shared or ambiguous responsibility.
Keep viewing, preparing, approving and changing sensitive records appropriately separated.
Record what changed, who changed it and when — so a question about the past has an answer.
A clear scope is a security property: software that claims less is easier to reason about.
Nothing that touches the ledger posts without a person approving it.
This website has no forms or accounts. Optional analytics runs only with your permission. See the privacy notice.