FAQS

Questions about governed document custody.

Clear answers for teams evaluating CVOR across platform, workflow, security, compliance, pricing, and deployment concerns.

Practical, direct, and procurement-friendly.

About the Platform

What is CVOR?

CVOR is governed document collection and custody infrastructure for sensitive workflows.

What kind of organizations use CVOR?

CVOR is designed for compliance, operations, legal, HR, hospitality, property, insurance, immigration, and KYC teams handling sensitive records.

Is CVOR a document management system?

No. CVOR focuses on governed document collection and custody, not broad internal document management.

How is CVOR different from a shared drive or client portal?

Shared drives and generic portals can store or receive files. CVOR governs the request, receipt, access, audit, retention, and lifecycle of sensitive documents.

Is CVOR self-serve?

No. CVOR is deployed through a sales-led onboarding process because sensitive workflows require context before rollout.

Workflows and Onboarding

Which workflows does CVOR support?

CVOR supports immigration, legal intake, employee onboarding, insurance, hospitality, property, and KYC document workflows.

How does onboarding start?

Onboarding starts with a workflow review covering document types, submitters, access boundaries, retention expectations, and deployment needs.

Can CVOR support multiple teams?

Yes. CVOR is designed for multi-workflow enterprise use where different teams need controlled document custody.

Does CVOR replace existing systems?

Usually no. CVOR governs the document collection layer and can sit alongside HR, legal, claims, property, or customer onboarding systems.

Can external people submit documents?

Yes. Submitters use a governed portal rather than sending documents through email or chat.

Security and Data

How are documents encrypted?

CVOR is built around AES-256-GCM application-layer encryption and encrypted object storage.

Where is data stored?

The reference architecture uses PostgreSQL for workflow metadata and S3-compatible object storage for encrypted documents.

Can submitters delete their own documents?

Deletion behavior depends on the workflow and organization policy. CVOR is designed to support governed lifecycle controls rather than unmanaged deletion.

How is access controlled?

Access is tenant-scoped and role-aware so sensitive documents are available only to appropriate users.

Does CVOR require MFA?

Yes. Mandatory multi-factor authentication is part of the enterprise access model.

Compliance and Governance

Is CVOR GDPR compliant?

CVOR is designed for GDPR compliance, including support for purpose limitation, access control, auditability, and retention governance. The organization remains responsible for its legal basis and policies.

Is CVOR ISO 27001 certified?

CVOR is built with ISO 27001-aligned controls. It should not be described as ISO 27001 certified unless certification has been completed.

Is CVOR SOC 2 compliant?

CVOR's architecture is prepared for SOC 2. It should not be described as SOC 2 compliant unless the relevant audit has been completed.

What happens after a retention period expires?

Retention sweeps and lifecycle controls are designed to support policy-driven cleanup according to the organization's defined rules.

Does CVOR create audit trails?

Yes. The platform is designed to record request, upload, access, review, and lifecycle events.

Pricing and Deployment

How is CVOR priced?

Pricing is scoped through guided onboarding based on workflow complexity, organizational scale, and governance requirements.

Is there a free trial?

CVOR is not positioned as a self-serve free-trial product. Evaluations are guided.

What deployment model does CVOR support?

The reference implementation supports a Docker-based local stack and a production path with hardened network, secret, and KMS-backed controls.

Can CVOR support procurement review?

Yes. CVOR is designed to support procurement, legal, compliance, and security review conversations.

Who should contact CVOR?

Teams that collect sensitive personal documents through email, WhatsApp, shared drives, or generic portals should contact CVOR to assess fit.