Security & Trust Center

Architecture Overview

SorvoAI uses a client-server architecture with a native desktop application (Electron) and a centralized API server. There is no web application by design — native apps provide stronger security boundaries, system-level integration, and reduced attack surface compared to browser-based alternatives.

Client (Your Device)

Server (Cloud)

Data Flow: What Stays Local vs. What Leaves

Stays on your device

Transmitted to server (encrypted via TLS 1.3)

Encryption Model

Authentication & Access Control

Data Retention & Deletion

AI Model Usage

Subprocessors

Compliance Roadmap

Reporting Vulnerabilities

If you discover a security vulnerability, please report it to security@sorvoai.com. We take all reports seriously and will respond within 48 hours.

Privacy Policy Terms of Service