Tenant isolation
Organization boundaries are enforced at the database and service layers, with tests proving customers cannot cross those boundaries.
Bills and contracts reveal sensitive operational details. Costivra keeps customer data separated, documents private, permissions narrow, and consequential actions under explicit approval.
Access, authority, and accountability are separate layers. That means a file cannot create permission, and permission cannot silently become an external action.
Organization boundaries are enforced at the database and service layers, with tests proving customers cannot cross those boundaries.
Original files stay in private storage and use short-lived signed access. Sensitive identifiers are masked when full display is unnecessary.
Users, services, agents, and integrations receive narrow permissions for the organization, resource, and action they need.
Consequential external actions require the configured approvals. Bank and payment instructions cannot be changed autonomously.
Corrections preserve the original extraction, editor, timestamp, reason, and evidence reference.
Instructions found inside documents, email, or OCR text are treated as data and cannot change policy or expand tool access.
Use the contact channel for a specific workflow or data-handling question. We will be clear about what exists today and what is still planned.