CAVELLIN LLC
SECURITY POLICY

1. Overview

Cavellin LLC takes the security of physician contract data seriously. Physicians uploading employment contracts to Cavellin are sharing sensitive personal and financial information. This Security Policy describes the technical and organizational measures Cavellin uses to protect that information.

How we handle your documents

Plain language, no hedging. This is what actually happens to a contract you upload.

Uploads go straight to private storage.

No public links, ever. Every contract you upload requires a signed, time-limited link to open. Even we cannot just grab a URL and read it.

We do not keep a spare copy of your contract's text.

The system reads your document once to run the analysis, and then only the structured findings are saved: the risks, the numbers, the recommendations. The raw text of the original document is not stored as its own separate copy.

After 365 days, access to your original file is cut off automatically.

We want to be accurate about what that means. Cutting off access makes the file permanently unreachable through Cavellin. It is gone on our end, for good. Full deletion of the underlying stored copy depends on our storage provider's own cleanup process, which is not something we can trigger on demand today. So we are not going to tell you we delete it. We tell you access is permanently gone, because that part is entirely true.

Ask us to delete your account and we remove your records.

That includes cutting off access to your uploaded files. One honest detail: this final step currently involves a quick manual action on our side rather than being fully automatic, so your deletion request is handled promptly by our team rather than the instant you click the button.

2. Data Encryption

  • All data transmitted between your browser and Cavellin is encrypted using TLS (Transport Layer Security).
  • Contract documents and analysis results are encrypted at rest using industry-standard encryption.
  • Payment data is processed exclusively by Stripe and is never stored on Cavellin's servers. Cavellin stores only a Stripe customer identifier.

3. Access Controls

  • Your contract data and analysis results are private to your authenticated account. No other user can access your data.
  • Cavellin employees and contractors access customer data only as necessary to operate and support the Service, and are bound by confidentiality obligations.
  • Administrative access to production systems is restricted and logged.
  • All internal function-to-function calls use shared secret authentication to prevent unauthorized invocation.

4. Authentication

  • Cavellin requires email verification for all new accounts.
  • Passwords are stored as cryptographic hashes and are never stored in plaintext.
  • Cavellin recommends using a unique, strong password for your Cavellin account.

5. Infrastructure Security

  • The Service is hosted on Base44 and Amazon Web Services, which maintain their own comprehensive security programs including SOC 2 compliance.
  • Cavellin conducts regular security reviews of its application code and entity-level access controls.
  • Role-based access control is enforced at the data layer: every entity query is scoped to the authenticated user.

6. AI Processing

  • Contract text is transmitted to Anthropic PBC for AI analysis processing. Anthropic is bound by data processing agreements requiring confidentiality.
  • Cavellin does not use your contract content to train general-purpose AI models.
  • Contract text is sent to Anthropic solely to run your analysis, and is automatically deleted according to Anthropic's own data retention policy. We deliberately do not quote a specific number of days here, because that number is Anthropic's to change and we would rather point you at the current policy than at a stale figure: Anthropic's API and data retention policy.

7. Incident Response

In the event of a data breach affecting your personal information, Cavellin will notify affected users without undue delay and within the timeframes required by applicable law, based on the jurisdiction in which each affected user resides. Notifications will describe the incident, the data affected, and the steps taken to address it. Where notification of affected individuals is required, Cavellin will also submit an electronic copy of the notice, together with a statement of the date and method of distribution, to the Montana Attorney General's Office of Consumer Protection at the same time it notifies affected Montana residents, as required by Montana law.

To report a security vulnerability or suspected incident, contact hello@cavellin.com with the subject line "Security."

8. Your Responsibilities

  • Use a unique, strong password for your Cavellin account.
  • Do not share your account credentials with others.
  • Log out of your account when using shared devices.
  • Notify Cavellin immediately at hello@cavellin.com if you suspect unauthorized access to your account.

9. Third-Party Services

Cavellin uses a limited set of third-party services to operate. Each is selected for its security practices and is bound by data protection agreements. Cavellin requires each subprocessor to notify Cavellin promptly upon discovery of any security incident affecting Cavellin customer data, so that Cavellin can meet its notification obligations under applicable law. See the Privacy Policy for the current list of subprocessors.

10. Updates to This Policy

Cavellin will update this policy as its security practices evolve. Material changes will be posted at cavellin.com/security and communicated per the Privacy Policy.

11. Contact

Security inquiries: hello@cavellin.com · cavellin.com