Compliance status

Your vault encrypts on your device first. Formal compliance programs will follow when they’re real and ready.

Coming later

HIPAA

We are not HIPAA certified and do not offer a BAA. Eirvr is a product direction, not a covered-entity or business-associate offering.

Coming later

GDPR

We design for data minimization (ciphertext in the vault), but we are not advertising a completed GDPR certification or a standard DPA package.

Not started

SOC 2

No SOC 2 engagement is in progress and we are not publishing a completion date. That work belongs on a later wave, not this beta.

Encryption is not immunity

Vault contents

Client-side AES-GCM means we cannot read file plaintext. That is the honest zero-knowledge claim.

Account metadata

Email, timestamps, and ciphertext blobs still exist on our side. We do not claim we have nothing to produce if lawfully required.

Payments

No Stripe trial is live on this beta. We are not advertising PCI processing or credit-card cancellation terms.

Questions?

Need a privacy or legal conversation? Email legal and we’ll help.

Contact Legal