Your vault encrypts on your device first. Formal compliance programs will follow when they’re real and ready.
We are not HIPAA certified and do not offer a BAA. Eirvr is a product direction, not a covered-entity or business-associate offering.
We design for data minimization (ciphertext in the vault), but we are not advertising a completed GDPR certification or a standard DPA package.
No SOC 2 engagement is in progress and we are not publishing a completion date. That work belongs on a later wave, not this beta.
Client-side AES-GCM means we cannot read file plaintext. That is the honest zero-knowledge claim.
Email, timestamps, and ciphertext blobs still exist on our side. We do not claim we have nothing to produce if lawfully required.
No Stripe trial is live on this beta. We are not advertising PCI processing or credit-card cancellation terms.