Platform
Security & Trust
01 — Approach
How we think about security
Organizations entrust EV Refurb with bills of materials, parts masters, supplier lists and product files. That information can be commercially sensitive, and protecting it is part of how we design and operate the platform — not something added later.
Our approach is straightforward: communicate the protections we have actually implemented and verified, explain them clearly, and never claim more than the evidence supports.
When a security control has limitations, we communicate those limitations where they are important to understanding the protection it provides.
02 — Data protection
Protecting the information you entrust to us
Secure connections
Information transmitted between your browser and EV Refurb is protected using encrypted connections, and the platform is configured to require secure connections.
Stored information
Information held in EV Refurb’s managed database and file storage is protected with encryption at rest provided by the underlying infrastructure.
Private file storage
Customer files are stored privately and are not made available through permanent public links. Access is provided only after authorization checks.
Temporary file access
Authorized document access uses time-limited links that expire automatically, reducing the risk of a shared or copied link becoming a lasting path to a file.
Browser and document protections
EV Refurb applies browser security protections and handles customer documents in ways designed to reduce the risk of uploaded content executing within the application.
03 — Access
Who can see your information
Organization-level access
Your organization’s documents and records are separated from other organizations’ information. These access boundaries are enforced at the data layer as well as through the application.
Server-side authorization
Access permissions are enforced by the platform’s server-side controls rather than relying only on what the interface displays or hides.
Account access and recovery
Access to your workspace requires authentication. Password recovery uses a time-limited link sent to the account’s verified email address.
Authorized staff access
Access to customer information by EV Refurb personnel is restricted to authorized roles, and security-relevant privileged access is recorded to support accountability.
04 — Uploads
Files you upload
File validation
Before a file is accepted, EV Refurb checks that the file is an allowed type and that its contents match what the file claims to be.
Malicious-content inspection
Uploaded files undergo malicious-content security inspection before release. Files are made available for use only after completing the required inspection.
When a file can’t be inspected
If EV Refurb cannot properly inspect a file, such as certain password-protected or encrypted files, we withhold it rather than allow an unchecked file into the platform.
Inspection stays within EV Refurb
Malicious-content inspection runs within EV Refurb rather than sending customer file contents to an external malware-scanning service.
Scope of inspection
EV Refurb’s malicious-content inspection is a security control, not a guarantee that every possible threat will be detected. A released file should not be interpreted as certified safe or malware-free.
05 — Accountability
Accountability
Security-relevant actions are recorded to support accountability and investigation.
Protected audit records
Security audit records are maintained separately from records of routine workspace and workflow activity, with access restricted to authorized personnel.
Designed to minimize sensitive content
Security audit records capture information needed to understand security-related events without recording the contents of customer documents.
07 — Governance
A governed security program
Security decisions at EV Refurb are documented, implemented, tested, and formally reviewed before we rely on them.
Our governance framework defines how security decisions are made, how controls are verified, how identified gaps are addressed, and how changes are reviewed. Public security statements follow the same discipline: they must be supported by implemented controls and evidence.
Security questions
Organizations evaluating EV Refurb may contact us with questions about the security practices described on this page.
