Contracts. Settlements. Financials. Your data stays yours.
OCTVE handles sensitive business data for artists, managers, and agencies. Protecting it is foundational to the product. This page summarizes the technical and organizational measures we use. For how we collect and use data, see our Privacy Policy and Terms of Service.
Last updated · June 3, 2026
Locked down, layer by layer.
From the infrastructure underneath to the row your record lives in, every layer has its own protections.
Infrastructure
OCTVE runs on managed cloud infrastructure operated by providers that maintain industry security certifications, including SOC 2, with physical and network controls we inherit. We do not operate our own data centers.
- Application hosting and edge delivery on Vercel
- Database, authentication, and file storage on Supabase, built on AWS
- Real-time messaging on a dedicated managed service
Encryption
Your data is encrypted moving and sitting still.
- All traffic served over TLS
- HTTPS enforced with HSTS, so browsers refuse to connect over plaintext
- Databases, backups, and uploaded files encrypted at rest by our infrastructure providers
Tenant isolation
OCTVE is multi-tenant, and every tenant’s data is isolated at the database layer.
- Row-Level Security enabled on application tables
- Access scoped to your organization on every query
- One organization can never read or modify another’s records
- Your OCTVE Intelligence conversations, uploaded documents, and generated context are isolated the same way, never accessible to other accounts
Access control
What a member can see and do is governed by their role in your organization, and your admins control it.
- Authentication handled by Supabase Auth, with multi-factor authentication supported
- Elevated sessions can be required to reach higher assurance levels
- Backend database privileges follow least-privilege principles; privileged routines are not callable by browser clients
- Platform-wide administrative access restricted to a single OCTVE operator
- Third-party API keys and signing secrets stored server-side, never exposed to the browser
Application security
Hardened headers, rate limits, and a log that nobody can rewrite.
- Strict Content-Security-Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, restrictive Permissions-Policy and Referrer-Policy
- Per-user and per-IP rate limits on sensitive backend endpoints to mitigate brute-force and abuse
- Security-relevant actions recorded to an append-only audit log that application users cannot alter
- User-generated content sanitized before rendering to defend against cross-site scripting
Payments
Payments and payouts are processed by Stripe, a PCI-DSS Level 1 certified provider.
- Card data handled directly by Stripe
- OCTVE never stores full card numbers on its servers
Your records. Your call.
Never trained on your business.
OCTVE Intelligence sends your request content to a third-party model provider (currently OpenAI) via its API to generate responses. Per the provider’s API data usage policies, data submitted through the API is not used to train its models. OCTVE does not train or fine-tune any model on your conversations, documents, or business data. Output is advisory: actions that change your records require your explicit confirmation.
Leave whenever. Take everything with you.
- Delete your account and organization data from Settings at any time. Deletion purges your organization’s records and removes associated files and billing customer data.
- After you cancel, your data remains intact for 30 days, with reminder emails, so you can reactivate. Then it is permanently deleted.
- Intelligence conversations are retained for 30 days so you can resume them, then automatically archived.
- After deletion we retain only a minimal compliance record: organization name, admin email, deletion date and reason. None of your business data.
Your rights, honored on both sides of the Atlantic.
We support data-subject rights under GDPR / UK GDPR and CCPA / CPRA, including access, correction, and deletion. We do not sell or share personal information for cross-context behavioral advertising, and we honor the Global Privacy Control (GPC) signal. For international transfers we rely on Standard Contractual Clauses and the equivalent UK and Swiss addenda. Data obtained via Google APIs is used only to provide user-facing features you engage with, consistent with Google’s Limited Use requirements. See the Privacy Policy for full detail and the Do Not Sell or Share page for California opt-out.
Who touches your data. The whole list.
We engage the following service providers under contracts that limit use of personal information to providing services to us, prohibit selling or sharing, and require appropriate security.
Supabase, Inc.
Database hosting, authentication, file storage
Privacy policyVercel, Inc.
Application hosting and edge delivery
Privacy policyRailway Corp.
Real-time infrastructure for the live assistant chat
Privacy policyStripe, Inc.
Payment processing, billing, marketplace payouts
Privacy policyOpenAI, L.L.C.
Model inference for OCTVE Intelligence features
Privacy policyGoogle LLC
Gmail, Calendar, Drive, Maps/Places APIs, only with your explicit OAuth consent
Privacy policyResend, Inc.
Transactional email delivery: password resets, invitations, notifications
Privacy policySoundcharts SAS
Public artist analytics data, only when you connect an artist
Privacy policyTolt
Affiliate program tracking
Privacy policyFound something? Tell us first.
We welcome responsible disclosure. If you believe you have found a security issue, email hello@octve.io with “Security” in the subject and steps to reproduce. Please give us a reasonable opportunity to investigate and remediate before any public disclosure. We do not pursue legal action against researchers who act in good faith and avoid privacy violations, data destruction, and service disruption.
A real inbox, read by real people.
Security questions or compliance requests (DPA, subprocessor notifications): hello@octve.io. Octve, LLC, a Wyoming limited liability company, mailing address 1930 Village Center Cir 3-2953, Las Vegas, NV 89134.
Serious about music. Serious about your data.
OCTVE holds your contracts, settlements, and financials, so protecting them is foundational to the product. Questions about security or compliance go straight to hello@octve.io.
Free migration · free 1:1 onboarding · cancel anytime