The short version: your commercial values never enter our permanent record. What we retain is what an auditor needs to check the work — fingerprints, verdicts, times — and nothing you'd mind an outsider seeing.
This isn't a legal document. It's the plain-language version of how the system actually handles your data, with the same rules the platform enforces on itself. If you need the formal terms for a procurement review, they're available on request.
The account that verifies what happened in your books is not the same account that carries out actions on your behalf. The executing identity holds only the permissions needed to create drafts; the verifying identity is read-only — a permission your accounting provider enforces, not a promise we ask you to trust. Every time we rotate credentials, the read-only ceiling is re-proven by attempting a write and keeping the refusal on record.
Two separate identities, two separate scopes, two separate roles: the doer never grades its own work. This is the same structural principle that keeps auditors independent of the companies they audit, expressed in software.
Capability and authority are two different things. The connection is technically capable of more than it is permitted to do, and the difference is written down rather than promised. What follows are the default rules for a new connection — yours are generated for your own setup and may differ. The right-hand list isn't a feature we haven't built yet; it's a set of actions this connection is structurally unable to perform in your account.
Verification runs as a separate read-only user inside your own Zoho — one your provider will not let write. We prove that ceiling rather than assert it: that user attempts a write, Zoho refuses, and the refusal is kept on record.
Default rules shown · v1.0.0 · once these are yours, changing any line requires your approval.
We cannot recover data after deletion. A deletion writes a tombstone recording that something was removed and why; the removed content is gone. This is a promise about privacy that comes with a cost to convenience, and it's a trade we make deliberately.
We cannot prevent changes made directly in your accounting system. If someone edits a quote in Zoho after our system has approved it, we detect the change on the next read-back and flag it — but no vendor should be able to stop you editing your own books. What the connection itself is permitted to do is enumerated under permissions.
We cannot promise anything about data our providers hold. Your accounting provider (Zoho) sees whatever it needs to see to operate its own system. The AI model provider we use for parsing sees the customer's message text at parse time; it does not see historical data, prices, or customer names. It does not retain what it saw. Both are named categories, not hidden dependencies.
The application runs in the UAE region (me-central-1). The AI model provider we use for parsing routes through their own regional infrastructure; the specific region depends on the model and can be requested for a specific customer. Your accounting provider stores your data wherever you've already configured it to.
You can export everything in the evidence store at any time, in a portable format that doesn't require us to read. You can request deletion at any time; the deletion is completed within seven days and recorded as an event you receive proof of. If you leave, the permanent record is retained per your retention policy (default: life-of-tenancy, which ends when the account closes); the evidence store is deleted on account closure unless you export it first.
Have a question this page doesn't answer? Email partners@pruvato.com with "Security question" in the subject — we usually reply in one business day and add the question to this page if it's the kind of thing someone else will ask too.