Security

What we actually do, concretely.

Transport

HTTPS everywhere. prevoca.app sits on a top-level domain that browsers refuse to load over plain HTTP, so there is no insecure fallback to misconfigure.

Storage and access

Files live in Cloudflare R2, records in Cloudflare D1. Presentations are tied to the account that uploaded them, and every owner-only route checks that ownership before it answers.

Delivery links

A delivery link contains a 256-bit random token. Possession of the link is the credential — which is why the link itself is the thing to guard — and the token space is far too large to guess or scan.

Sign-in

No passwords. You sign in by email link or with Google. Sign-in tokens are stored hashed, so a copy of our database contains nothing that signs anyone in.

Internal traffic

The generation service and the app authenticate to each other with signed requests; the generation side holds no storage credentials of its own.

Payments

Card data never touches our servers. Paddle handles checkout end to end as merchant of record.

Data minimisation

The less we hold, the less an incident can expose — see the privacy page for what we deliberately don't collect.

Found something?

Report it to hello@prevoca.app. We read every report and we'd rather hear it from you.

Questions about any of this: hello@prevoca.app. Prevoca is operated by KumoAlpha AI Technologies Co., Ltd. (酷摩智能科技有限公司), Taiwan.