

Last updated: July 2026
We take the security of the Service and your data seriously and maintain administrative, technical, and organizational measures designed to protect it. These include encryption of data in transit and at rest, access controls and least-privilege practices, secure authentication with support for multi-factor authentication, dependency and vulnerability monitoring, logging and alerting, and secure hosting with reputable infrastructure providers. A fuller description of the measures we apply to personal data is set out in our Privacy Policy and Data Processing Agreement.
No system is perfectly secure, and we cannot guarantee absolute security. You play an important role in keeping your account safe: use a strong, unique password, enable multi-factor authentication where available, keep your credentials confidential, and notify us immediately of any suspected unauthorized access at security@uova.io.
We welcome reports from security researchers and the public. If you believe you have found a security vulnerability in the Service, please report it to security@uova.io with enough detail for us to reproduce and validate the issue.
Safe Harbor — If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, will work with you to understand and resolve the issue promptly, and will not pursue or support legal action against you related to your report.
Guidelines — Please: give us a reasonable time to investigate and remediate before any public disclosure; make a good-faith effort to avoid privacy violations, data destruction, and service disruption; only interact with accounts you own or have explicit permission to test; and do not access, modify, or exfiltrate data that does not belong to you beyond the minimum necessary to demonstrate the issue.
Out of Scope — Denial-of-service attacks, social engineering of our staff or users, physical attacks, spam, and automated scanning that degrades the Service are not authorized under this policy.
In the event of a personal-data breach affecting your information, we will notify affected users and applicable authorities as required by law and in accordance with our contractual commitments (including, for business customers, the notification timelines in our Data Processing Agreement). We maintain incident-response procedures to detect, investigate, contain, and remediate security incidents.