Security & Confidentiality
Your data is hosted in Europe on infrastructure operated by SOC 2 Type II and ISO 27001 certified providers — Supabase for the database and storage (eu-central-1 region, Frankfurt), Vercel for the frontend and API routes (cdg1 region, Paris). Communications are encrypted with TLS 1.2+ in transit, AES-256 at rest. Individual authentication with optional MFA (TOTP), strict isolation between organisations audited in May 2026. Olifin B.V. itself is not SOC 2 or ISO 27001 certified at this time; an ISO 27001 programme is planned for 2027. Home · Features · Detailed security page
Why is this safer than an Excel file?
An Excel file can be copied, emailed to the wrong recipient, stored on an unencrypted USB stick, or lost with a stolen laptop. On Jolv, your valuation data is protected by individual authentication, AES-256 encryption at rest, and row-level security policies on the database and storage layer that ensure only authorised members of your organisation can access your data.
Secure authentication
Each user has an individual password-protected account with optional MFA (TOTP via authenticator app). Sessions are handled with JWT tokens that refresh automatically. Passwords are never stored in clear text.
Data isolation (RLS)
Row-level security policies on the database and on storage objects ensure that each user only sees the data attached to their organisation and to the funds they have been granted access to. This isolation is enforced by the database itself, not by the interface: an out-of-scope query returns no rows, whatever the access path.
Encryption in transit (TLS)
All communications between your browser and our servers are encrypted via HTTPS / TLS 1.2 or higher. Data cannot be intercepted during transfer.
Encryption at rest (AES-256)
Data stored in the database and in document storage is encrypted with the AES-256 algorithm at the Supabase infrastructure level — the same standard used by banking and government institutions.
European hosting
Database and storage hosted by Supabase in the eu-central-1 region (Frankfurt, AWS). Frontend and API routes hosted by Vercel in the cdg1 region (Paris, AWS). Both infrastructure providers are SOC 2 Type II and ISO 27001 certified; signed Data Processing Agreements (DPAs) are available upon request.
Automatic backups
Supabase performs daily automatic AES-256 encrypted backups with 14-day point-in-time restore (Pro plan). Your data remains recoverable even in the event of a technical incident.
No local data
All data stays on the server side. Nothing is stored locally on your computer, eliminating leak risk in case of equipment loss or theft.
Traceability & audit
Every sensitive action (valuation creation, holding modification, admin access) is timestamped and attached to the authenticated user in dedicated audit logs. These logs make it possible to trace changes made to the data.
Video meetings (Jitsi Meet)
Video conferencing links generated from Jolv use Jitsi Meet. Audio and video communications are encrypted in transit (TLS). End-to-end encryption (E2EE) is an option available on Jitsi Meet depending on the browser and client used by participants. Generated links are unique per meeting.
Artificial intelligence (Jolv AI)
Jolv AI only processes data from your organisation, with strict per-user access and multi-tenant isolation. AI queries execute in read-only mode on the scope your user has access to. No client data is used to train third-party AI models. A detailed list of AI providers and their hosting regions is available in the privacy policy.