Updated August 17, 2026

Security

How Ergova protects customer data and platform reliability

Our commitment

Ergova uses technical and organizational measures designed to protect customer information. No online service can eliminate all security risk, and we do not claim that Ergova is completely secure or free from vulnerabilities.

This page summarizes how we approach authentication, access control, data protection, payments, infrastructure, and vulnerability reporting. It is not a certification, audit report, or guarantee of outcomes.

Authentication and access

Customers authenticate to Ergova through a third-party identity and authentication provider. Sign-in, sessions, and account recovery flows are handled through that provider together with Ergova's application controls. Password storage and related credential security for those sign-in methods are handled by the identity provider, not by independently operated Ergova password databases.

Where additional authentication protections are available through the identity provider or Ergova account security settings, we encourage customers to enable them. Ergova does not claim that multi-factor authentication is mandatory for all accounts.

Within each organization, Ergova uses role-based permissions so owners, admins, dispatchers, and technicians can be limited to the actions and information their work requires. Organization administrators are responsible for assigning appropriate roles and removing access when someone no longer needs it.

Organization and data access

Ergova is a multi-tenant business application. We use organization membership and authorization controls designed to restrict users to data they are permitted to access for their company.

Ergova uses multiple authorization controls, including organization-scoped application access and database-level access controls where applicable, together with server-side authorization checks as part of how the product is built. We do not claim flawless isolation, formal verification, or that cross-tenant access is impossible.

Encryption and data protection

Ergova is designed so customer traffic to the service is protected with encryption in transit (HTTPS/TLS). Encryption at rest is provided through our infrastructure providers as part of how those platforms store data.

Ergova must process certain data to provide the service, so we do not claim end-to-end encryption of all customer content. We also do not claim specific algorithms, customer-managed keys, or field-level encryption on this page.

Application secrets and sensitive credentials are stored using protected environment and configuration mechanisms and are not intentionally exposed in client-side application code.

Payment security

Subscription billing and customer payment processing used with Ergova are provided through Stripe. Ergova is designed to avoid directly storing full payment-card numbers on Ergova systems. Card and payment-method details are handled by Stripe according to Stripe's terms and security practices.

Using Stripe does not mean Ergova itself is PCI DSS certified. Any questions about payment flows for your organization can be directed through the contacts below or our Terms of Service.

Infrastructure and providers

Ergova relies on specialized service providers for hosting, databases, authentication, payments, communications, analytics, and related platform functions. A current list of subprocessors is maintained on our Subprocessors page.

Reliability and data protection also depend on those providers' controls. A provider's certifications or compliance programs do not automatically certify Ergova. We do not publish detailed internal architecture on this page. If you are evaluating Ergova for your organization and need deeper diligence, contact our team.

Monitoring and incidents

Ergova uses application and operational logging to help operate, troubleshoot, and improve the service. We investigate suspected security incidents and take remediation steps we determine are appropriate.

Where required by applicable law or contractual obligations—including our Data Processing Addendum where it applies—we provide notifications related to security incidents. We do not promise a fixed public notification deadline on this page, and we do not claim 24/7 security operations center monitoring or continuous human threat surveillance.

Shared responsibility

Securing an Ergova organization is a shared effort. Customers remain responsible for practices such as:

  • Protecting login credentials and devices used to access Ergova
  • Assigning appropriate user roles and permissions
  • Removing access when users leave or no longer need the product
  • Configuring integrations carefully and reviewing connected services
  • Reporting suspected account compromise or unusual activity promptly

Shared responsibility does not reduce Ergova's obligation to design and operate the service with appropriate security measures.

Vulnerability reporting

If you believe you have found a security vulnerability or have a security concern about Ergova, please contact us. Include enough detail for us to reproduce or investigate the issue—such as the affected URL or product area, steps to reproduce, and the potential impact—while avoiding unnecessary sensitive customer data.

We do not currently operate a public bug bounty, monetary reward, or formal safe-harbor program, and we do not promise a specific response SLA on this page.

Security contact

For security questions and vulnerability reports, email legal@ergova.co. Ergova Technologies, Inc. uses this address for legal and privacy inquiries as well; please include "Security" in the subject when reporting a vulnerability or concern.

Product and account support

For product and account questions, visit Contact Ergova support or email support@ergova.co. Related policies: Privacy Policy · Terms of Service · Data Processing Addendum.

Ongoing improvement

Security is an ongoing discipline. As Ergova evolves, we continue to refine systems, access controls, and operational practices. We do not treat security as a one-time checklist.