Platform

Security & Trust

01 — Approach

How we think about security

Organizations entrust EV Refurb with bills of materials, parts masters, supplier lists and product files. That information can be commercially sensitive, and protecting it is part of how we design and operate the platform — not something added later.

Our approach is straightforward: communicate the protections we have actually implemented and verified, explain them clearly, and never claim more than the evidence supports.

When a security control has limitations, we communicate those limitations where they are important to understanding the protection it provides.

02 — Data protection

Protecting the information you entrust to us

Secure connections

Information transmitted between your browser and EV Refurb is protected using encrypted connections, and the platform is configured to require secure connections.

Stored information

Information held in EV Refurb’s managed database and file storage is protected with encryption at rest provided by the underlying infrastructure.

Private file storage

Customer files are stored privately and are not made available through permanent public links. Access is provided only after authorization checks.

Temporary file access

Authorized document access uses time-limited links that expire automatically, reducing the risk of a shared or copied link becoming a lasting path to a file.

Browser and document protections

EV Refurb applies browser security protections and handles customer documents in ways designed to reduce the risk of uploaded content executing within the application.

03 — Access

Who can see your information

Organization-level access

Your organization’s documents and records are separated from other organizations’ information. These access boundaries are enforced at the data layer as well as through the application.

Server-side authorization

Access permissions are enforced by the platform’s server-side controls rather than relying only on what the interface displays or hides.

Account access and recovery

Access to your workspace requires authentication. Password recovery uses a time-limited link sent to the account’s verified email address.

Authorized staff access

Access to customer information by EV Refurb personnel is restricted to authorized roles, and security-relevant privileged access is recorded to support accountability.

04 — Uploads

Files you upload

File validation

Before a file is accepted, EV Refurb checks that the file is an allowed type and that its contents match what the file claims to be.

Malicious-content inspection

Uploaded files undergo malicious-content security inspection before release. Files are made available for use only after completing the required inspection.

When a file can’t be inspected

If EV Refurb cannot properly inspect a file, such as certain password-protected or encrypted files, we withhold it rather than allow an unchecked file into the platform.

Inspection stays within EV Refurb

Malicious-content inspection runs within EV Refurb rather than sending customer file contents to an external malware-scanning service.

Scope of inspection

EV Refurb’s malicious-content inspection is a security control, not a guarantee that every possible threat will be detected. A released file should not be interpreted as certified safe or malware-free.

05 — Accountability

Accountability

Security-relevant actions are recorded to support accountability and investigation.

Protected audit records

Security audit records are maintained separately from records of routine workspace and workflow activity, with access restricted to authorized personnel.

Designed to minimize sensitive content

Security audit records capture information needed to understand security-related events without recording the contents of customer documents.

06 — AI governance

AI with human authority

AI recommends. Humans approve.

AI can surface insights, identify patterns, and recommend actions. Human authority remains central to governed decisions, and AI cannot independently change the rules that govern the platform.

07 — Governance

A governed security program

Security decisions at EV Refurb are documented, implemented, tested, and formally reviewed before we rely on them.

Our governance framework defines how security decisions are made, how controls are verified, how identified gaps are addressed, and how changes are reviewed. Public security statements follow the same discipline: they must be supported by implemented controls and evidence.

Security questions

Organizations evaluating EV Refurb may contact us with questions about the security practices described on this page.