CAVELLIN LLC
SECURITY POLICY
Cavellin LLC takes the security of physician contract data seriously. Physicians uploading employment contracts to Cavellin are sharing sensitive personal and financial information. This Security Policy describes the technical and organizational measures Cavellin uses to protect that information.
Plain language, no hedging. This is what actually happens to a contract you upload.
Uploads go straight to private storage.
No public links, ever. Every contract you upload requires a signed, time-limited link to open. Even we cannot just grab a URL and read it.
We do not keep a spare copy of your contract's text.
The system reads your document once to run the analysis, and then only the structured findings are saved: the risks, the numbers, the recommendations. The raw text of the original document is not stored as its own separate copy.
After 365 days, access to your original file is cut off automatically.
We want to be accurate about what that means. Cutting off access makes the file permanently unreachable through Cavellin. It is gone on our end, for good. Full deletion of the underlying stored copy depends on our storage provider's own cleanup process, which is not something we can trigger on demand today. So we are not going to tell you we delete it. We tell you access is permanently gone, because that part is entirely true.
Ask us to delete your account and we remove your records.
That includes cutting off access to your uploaded files. One honest detail: this final step currently involves a quick manual action on our side rather than being fully automatic, so your deletion request is handled promptly by our team rather than the instant you click the button.
In the event of a data breach affecting your personal information, Cavellin will notify affected users without undue delay and within the timeframes required by applicable law, based on the jurisdiction in which each affected user resides. Notifications will describe the incident, the data affected, and the steps taken to address it. Where notification of affected individuals is required, Cavellin will also submit an electronic copy of the notice, together with a statement of the date and method of distribution, to the Montana Attorney General's Office of Consumer Protection at the same time it notifies affected Montana residents, as required by Montana law.
To report a security vulnerability or suspected incident, contact hello@cavellin.com with the subject line "Security."
Cavellin uses a limited set of third-party services to operate. Each is selected for its security practices and is bound by data protection agreements. Cavellin requires each subprocessor to notify Cavellin promptly upon discovery of any security incident affecting Cavellin customer data, so that Cavellin can meet its notification obligations under applicable law. See the Privacy Policy for the current list of subprocessors.
Cavellin will update this policy as its security practices evolve. Material changes will be posted at cavellin.com/security and communicated per the Privacy Policy.
Security inquiries: hello@cavellin.com · cavellin.com