Security at DOVA

This page explains, in plain English, how DOVA handles your manufacturing data — how it is encrypted, who can see it, where it is stored, how people log in, and what compliance work is in progress. We update this page as things change. Last updated: August 20, 2026.

How we protect your data

All traffic between your browser and DOVA is encrypted using HTTPS (TLS 1.2 or higher). Your data is never transmitted in plain text.

Data at rest is encrypted using industry-standard AES-256 encryption, managed by our database provider (Supabase) and hosting provider (Vercel / AWS).

Database backups are taken automatically and retained for disaster recovery.

Who can see what

DOVA uses role-based access control. Every user has one of five roles, and the system only shows them the data their role allows:

• Global Admin — DOVA platform staff only.

• Company Admin — full access across your company.

• Location Manager — access scoped to their location.

• Operator — access scoped to their department.

• Viewer — read-only access.

Access rules are enforced on every database query, not just in the user interface. A user cannot see or change data outside their scope even by crafting direct requests.

Where your data lives

Application hosting: Vercel (US regions, backed by AWS).

Database: Supabase (managed PostgreSQL, US regions, backed by AWS).

We do not store customer data on personal devices, laptops, or employee workstations.

Login and identity

Email + password login with secure password hashing handled by Supabase Auth.

Two-factor authentication (authenticator-app codes) is available to every user, enforced for DOVA’s own administrative accounts, and each customer can require it for their admins and location managers with one company setting.

A lost authenticator can be reset by a company admin; every two-factor change is recorded in the audit trail.

Session cookies are HTTP-only and flagged secure.

Compliance roadmap

DOVA is not yet SOC 2 certified. We are transparent about this — no fake badges.

A SOC 2 readiness program is actively underway: security controls, policies, and audit evidence are being built and operated now, so an audit can start as soon as a customer requires the report.

Data Processing Agreement (DPA): available below and on request.

Privacy practices are described in our Privacy Policy (link below).

Subprocessors

We use a small number of trusted service providers to run DOVA. Each one is selected for its own security posture:

• Supabase — managed database, authentication, and storage.

• Vercel — application hosting and deployment.

• Stripe — payment processing (PCI-DSS compliant).

• Resend — transactional email delivery.

• Google — Drive / Sheets schedule-file sync (only for customers who connect it).

• Microsoft — SharePoint / OneDrive schedule-file sync (only for customers who connect it).

The full list with regions and data categories is public at dovamfg.com/subprocessors.

Security questions or concerns?

If you have a security question, a compliance request, or need our DPA or subprocessor list, contact us directly. We respond within two business days.

security@dovamfg.com