FAQS

Questions about governed document custody.

Clear answers for teams evaluating CVOR across platform, workflow, security, compliance, pricing, and deployment concerns.

Practical, direct, and procurement-friendly.

About the Platform

What is CVOR?

CVOR is governed document collection and custody infrastructure for sensitive workflows. It helps organizations request, receive, review, retain, and audit sensitive documents without relying on ordinary inboxes, chat threads, or unmanaged shared folders.

Explore the CVOR platform ->
What is governed document custody?

Governed document custody is the controlled handling of sensitive documents after they are requested or submitted. It combines encrypted storage, access control, audit trails, retention rules, and lifecycle governance so the organization can show what happened to each document and why it is still being held.

See how governed custody works ->
How should organizations collect sensitive documents securely?

Organizations should collect sensitive documents through a governed workflow that defines the request, verifies the submitter path, limits access, records activity, and applies retention rules. Email, WhatsApp, and shared drives can move files, but they do not reliably govern request status, access history, forwarding, deletion, or lifecycle policy.

Read why email and WhatsApp fail document workflows ->
What kind of organizations use CVOR?

CVOR is designed for compliance, operations, legal, HR, hospitality, property, insurance, immigration, and KYC teams handling sensitive records. These teams usually need stronger evidence of request history, access governance, auditability, and retention than ordinary file sharing tools provide.

Is CVOR a document management system?

No. CVOR focuses on governed document collection and custody, not broad internal document management. It is built for the exchange layer where external people submit sensitive records and internal teams need controlled receipt, review, access, and retention.

How is CVOR different from a shared drive or client portal?

Shared drives and generic portals can store or receive files. CVOR governs the request, receipt, access, audit, retention, and lifecycle of sensitive documents, so the workflow is accountable from the first request through final cleanup.

Compare governed custody with common alternatives ->
Is CVOR self-serve?

No. CVOR is deployed through a sales-led onboarding process because sensitive workflows require context before rollout. The team reviews document types, participants, access boundaries, retention expectations, and governance requirements before deployment.

Workflows and Onboarding

Which workflows does CVOR support?

CVOR supports immigration, legal intake, employee onboarding, insurance, hospitality, property, and KYC document workflows. It is best suited to workflows where passports, identity records, payroll files, claims evidence, proof of address, or regulated customer records need accountable handling.

Review participant document collection workflows ->
How does onboarding start?

Onboarding starts with a workflow review covering document types, submitters, access boundaries, retention expectations, and deployment needs. This helps CVOR map the governed collection process before sensitive records begin moving through the platform.

Request a workflow review ->
Can CVOR support multiple teams?

Yes. CVOR is designed for multi-workflow enterprise use where different teams need controlled document custody. Access can be scoped by tenant, role, and workflow so separate teams can handle sensitive records without creating unnecessary visibility.

Does CVOR replace existing systems?

Usually no. CVOR governs the document collection layer and can sit alongside HR, legal, claims, property, or customer onboarding systems. The aim is to control how sensitive documents are requested, received, audited, retained, and handed into downstream processes.

Can external people submit documents?

Yes. Submitters use a governed portal rather than sending documents through email or chat. That gives the organization a clearer record of what was requested, what was submitted, when it arrived, and who accessed it.

Document Collection Use Cases

How should immigration teams collect passports and visa documents securely?

Immigration teams should collect passports, visas, proof of address, identity records, and supporting evidence through a governed workflow rather than email attachments or WhatsApp messages. The workflow should record who requested the document, when it was submitted, who accessed it, and how long it should be retained.

See immigration document collection ->
How should law firms collect client documents securely?

Law firms should collect client identity records, case evidence, signed forms, and supporting documents through controlled intake rather than shared inboxes or generic upload links. A governed intake workflow gives legal teams clearer access boundaries, audit history, and lifecycle control around sensitive client material.

See legal client document intake ->
How should HR teams collect right-to-work and onboarding documents?

HR teams should collect right-to-work evidence, identity records, contracts, payroll files, and onboarding documents through a workflow that controls access and retention from the start. This reduces scattered copies across inboxes, downloads, and shared drives while creating a clearer record of the onboarding document trail.

See employee onboarding document workflows ->
How can insurers collect claims evidence with an audit trail?

Insurers should collect claims evidence through a system that records request, upload, review, access, and lifecycle events. A governed workflow helps teams preserve context around submitted evidence without relying on forwarded attachments, local downloads, or incomplete mailbox history.

See insurance document workflows ->
How should hotels collect guest ID documents securely?

Hotels that need guest identity documents should avoid informal collection through ordinary email, messaging apps, or unmanaged photocopy workflows. A governed collection process gives the hotel clearer control over submission, access, retention, and deletion expectations.

See hotel guest document collection ->
How should property teams collect tenant documents securely?

Property teams often collect passports, proof of address, bank statements, references, lease records, and right-to-rent evidence. These documents should move through a governed workflow that limits access, records activity, and applies retention rules instead of remaining scattered across inboxes and shared folders.

See property document workflows ->
What is the best way to collect KYC documents securely?

KYC and customer due diligence teams should collect identity documents, proof of address, corporate records, and supporting evidence through a controlled workflow with audit trails, access governance, and lifecycle rules. The collection layer should support compliance review without turning sensitive records into unmanaged attachments.

See KYC document collection ->

Security and Data

How are documents encrypted?

CVOR is built around AES-256-GCM application-layer encryption and encrypted object storage. Sensitive document handling is designed around layered controls rather than a single storage boundary.

Review security and governance controls ->
Where is data stored?

The reference architecture uses PostgreSQL for workflow metadata and S3-compatible object storage for encrypted documents. Production deployment details are reviewed as part of onboarding because storage, region, retention, and governance requirements can vary by organization.

Can submitters delete their own documents?

Deletion behavior depends on the workflow and organization policy. CVOR is designed to support governed lifecycle controls rather than unmanaged deletion, so retention and cleanup can be aligned to the organization's policy and legal basis.

How is access controlled?

Access is tenant-scoped and role-aware so sensitive documents are available only to appropriate users. The access model is designed for teams that need clear boundaries between organizations, workflows, reviewers, and document types.

Does CVOR require MFA?

Yes. Mandatory multi-factor authentication is part of the enterprise access model. Invite-only onboarding also helps prevent uncontrolled registration into sensitive workflows.

Compliance and Governance

Is CVOR GDPR compliant?

CVOR is designed for GDPR compliance, including support for purpose limitation, access control, auditability, and retention governance. The organization remains responsible for its legal basis, privacy notices, retention policies, and controller obligations.

Review CVOR's compliance posture ->
Is CVOR ISO 27001 certified?

CVOR is built with ISO 27001-aligned controls. It should not be described as ISO 27001 certified unless certification has been completed.

Is CVOR SOC 2 compliant?

CVOR's architecture is prepared for SOC 2. It should not be described as SOC 2 compliant unless the relevant audit has been completed.

What happens after a retention period expires?

Retention sweeps and lifecycle controls are designed to support policy-driven cleanup according to the organization's defined rules. This helps teams move from informal deletion practices to governed retention enforcement.

Does CVOR create audit trails?

Yes. The platform is designed to record request, upload, access, review, and lifecycle events. Audit trails help teams answer practical governance questions such as who requested a document, when it arrived, who viewed it, and what happened next.

Review audit and observability controls ->

Pricing and Deployment

How is CVOR priced?

Pricing is scoped through guided onboarding based on workflow complexity, organizational scale, and governance requirements. CVOR is not sold as a one-size-fits-all self-serve subscription because sensitive document workflows usually require careful scoping.

Review CVOR pricing approach ->
Is there a free trial?

CVOR is not positioned as a self-serve free-trial product. Evaluations are guided so the team can understand the workflow, document types, access model, retention needs, and deployment path before rollout.

What deployment model does CVOR support?

The reference implementation supports a Docker-based local stack and a production path with hardened network, secret, and KMS-backed controls. Deployment requirements are reviewed with each organization before production use.

Can CVOR support procurement review?

Yes. CVOR is designed to support procurement, legal, compliance, and security review conversations. The platform narrative is built around controls, traceability, retention, and operational governance rather than generic file storage.

Who should contact CVOR?

Teams that collect sensitive personal documents through email, WhatsApp, shared drives, or generic portals should contact CVOR to assess fit. This includes organizations handling passports, visas, payroll records, right-to-work evidence, claims files, tenant documents, client records, or KYC evidence.

Request a demo ->