Patravo Security Policy
- Effective Date
- June 28, 2026
- Last Updated
- June 28, 2026
Contents
Patravo is operated by Venlorin LLC.
1. Plain-English Summary
Patravo is built for youth-serving organizations. That means security is not just a technical requirement. It is part of youth safety, family privacy, and responsible organization management.
Patravo protects information through technical, administrative, and organizational safeguards. These safeguards are designed to protect youth information, parent and guardian information, organization rosters, events, attendance, communications, files, photos, videos, and account access.
In plain English:
- Patravo treats security as a core product requirement.
- Patravo uses role-based access controls so users see information based on their role, group, guardian relationship, and organization settings.
- Patravo uses Clerk authentication and Clerk Client Trust signals to help protect account access.
- Patravo uses encryption in transit.
- Patravo uses service providers for hosting, compute, authentication, database services, storage, email, and related infrastructure.
- Private files and media are stored privately and accessed through signed URLs or other controlled access methods.
- Patravo does not use email open tracking or click tracking.
- Patravo designs logs to avoid storing customer content, youth roster details, message contents, media contents, and other unnecessary personal information.
- Patravo maintains procedures for security incidents, vulnerability review, vendor review, backups, and recovery.
- No system is 100% secure.
- Security concerns should be reported to security@patravo.com.
If there is an emergency or immediate risk of harm, contact emergency services or the appropriate authorities first.
2. Our Security Commitments
Patravo’s security commitments are part of the product.
- Security supports youth safety. Patravo is designed for youth-serving organizations, so security decisions are evaluated through a youth-safety lens.
- Privacy and security are designed together. Patravo does not treat security as separate from privacy. Protecting youth and family information requires both.
- Organization data is protected by permissions. Access to organization information depends on role, group membership, guardian relationship, administrative permissions, and organization settings.
- Youth information receives extra care. Youth names, contact details, photos, videos, attendance, event participation, and communications are treated as sensitive organization information.
- Account protection is layered. Patravo uses Clerk authentication, session controls, and Clerk Client Trust signals where available, and plans to require multi-factor authentication for organization administrators.
- Administrative access is restricted. Patravo limits administrative access to users and personnel who need it for authorized purposes.
- Data is encrypted in transit. Patravo uses secure connections to protect data as it moves between users, apps, and Patravo services.
- Data is protected at rest where appropriate. Patravo uses infrastructure and storage providers that support safeguards for stored data.
- Private files and media are controlled. Private files and media are stored privately and accessed through signed URLs or other controlled access methods.
- Public media is separated intentionally. Media intended for public organization websites may be stored or served separately from private organization media.
- Email tracking is disabled. Patravo does not use email open tracking or click tracking.
- Logs are minimized. Patravo designs logs to avoid storing customer content, youth roster details, message contents, media contents, and other unnecessary personal information.
- Security events are monitored. Patravo may monitor technical logs, authentication events, administrative activity, errors, and abuse signals to protect the service.
- Vendors are reviewed. Patravo reviews service providers based on the role they perform, the data they process, and available security documentation.
- Incident response matters. Patravo maintains procedures for reviewing, containing, investigating, and responding to suspected security incidents.
- Responsible disclosure is supported. Patravo welcomes good-faith security reports through security@patravo.com.
- Security data is not advertising data. Patravo does not use security logs, diagnostic information, or customer content to build advertising profiles.
- No AI use. Patravo does not use AI features or AI providers, and Patravo does not use customer content to train AI models.
- No false guarantees. Patravo works to protect the service, but no system is 100% secure.
3. Scope
This Security Policy applies to:
- https://patravo.com
- Patravo’s public website
- Patravo’s web app
- Patravo’s iOS app
- Patravo’s Android app
- Patravo organization workspaces
- Public organization websites powered by Patravo
- Authentication systems
- Account and administrator tools
- Roster, group, role, event, attendance, message, file, photo, video, and media features
- Support communications
- Security reporting channels
- Related services that link to this Security Policy
Third-party services used with Patravo may have their own security practices, privacy policies, and terms. Patravo reviews service providers, but Patravo does not control every part of a third-party provider’s infrastructure.
4. Shared Responsibility
Security is a shared responsibility.
Patravo secures the platform. Organizations must configure and use the platform responsibly. Users must protect their accounts and devices.
4.1 Patravo’s Responsibilities
Patravo is responsible for:
- Platform security
- Secure software development practices
- Authentication systems
- Role and permission systems
- Infrastructure safeguards
- Vendor and subprocessor review
- Security monitoring
- Incident-response procedures
- Backup and recovery procedures
- Vulnerability review
- Responsible disclosure handling
- Protecting production systems from unauthorized access
- Limiting internal access to legitimate business, support, security, legal, or operational needs
4.2 Organization Responsibilities
Organizations are responsible for secure and appropriate use of Patravo.
Organizations should:
- Invite only authorized users.
- Assign correct roles.
- Remove users who are no longer authorized.
- Review administrator access regularly.
- Verify parent and guardian relationships.
- Use youth-protection settings correctly.
- Configure public sharing carefully.
- Protect exported data.
- Avoid storing unnecessary sensitive information.
- Report suspected account compromise.
- Report unsafe or unauthorized behavior.
- Follow their own youth-protection, safeguarding, supervision, training, screening, reporting, transportation, event, and recordkeeping requirements.
- Follow applicable council, district, chartered organization, national organization, school, church, camp, nonprofit, or governing-body requirements.
Patravo provides tools. Organizations remain responsible for leadership, supervision, program safety, legal compliance, and judgment.
4.3 Individual User Responsibilities
Users should:
- Use strong passwords.
- Never share accounts.
- Protect their email accounts.
- Protect their devices.
- Use two-factor authentication where available.
- Keep apps, browsers, and operating systems updated.
- Report suspicious activity.
- Log out of shared devices.
- Avoid downloading or exporting data to insecure locations.
- Tell an organization administrator or Patravo if they believe their account was compromised.
Youth users should not use Patravo to hide unsafe behavior. If a youth user feels unsafe, pressured, threatened, or uncomfortable, they should contact a parent, guardian, trusted adult, organization leader, emergency services, or the appropriate authority.
5. Youth Safety and Security
Patravo is designed for youth-serving organizations, including troops, packs, crews, ships, posts, councils, chartered organizations, camps, schools, churches, clubs, nonprofits, and similar groups.
In Patravo, security is not only about preventing unauthorized logins. It is also about making sure the right adults, guardians, and organization representatives have appropriate visibility while limiting access for everyone else.
Patravo’s youth-safety security principles include:
- Youth information should be visible only to authorized users.
- Access should depend on role, group, guardian relationship, organization membership, and organization settings.
- Private organization workspaces should not be public by default.
- Public organization pages should be separate from private organization workspaces.
- Administrator access should be limited to trusted and authorized users.
- Youth-protection settings should support appropriate adult oversight and guardian involvement.
- Patravo should not be used to create secret or unsafe adult-to-youth communication.
- Administrative and security events may be logged for accountability.
- Reports and moderation tools may help organizations respond to unsafe behavior.
- Patravo may preserve records or restrict access when needed for safety, legal, or security reasons.
Patravo’s security features support youth protection, but they do not replace adult supervision, mandatory reporting, emergency services, child protective services, law enforcement, trained youth-protection leadership, or an organization’s own policies.
If there is an emergency or immediate risk of harm, contact emergency services or the appropriate authorities first.
6. Data Protected by Patravo
Patravo’s safeguards are designed to protect data such as:
- Account information
- Authentication information
- Youth member information
- Parent and guardian information
- Organization rosters
- Groups, patrols, dens, teams, committees, and roles
- Guardian relationships
- Events and attendance records
- RSVP records
- Permission and consent records
- Messages and announcements
- Comments and event discussions
- Photos and videos
- File attachments
- Public website content
- Administrative settings
- Audit and security records
- Billing and subscription records
- Technical logs and diagnostic information
Some information is more sensitive than other information. Youth information, guardian relationships, attendance records, medical or emergency information, private messages, and media involving youth should be handled with extra care.
7. Data Minimization
Patravo’s security approach includes collecting and storing only what is needed to provide, protect, and operate the service.
Patravo does not use security or diagnostic information for advertising.
Patravo designs application logs to avoid storing customer content, youth roster details, message contents, media contents, and other unnecessary personal information.
Patravo may process limited technical logs and security metadata when needed for:
- Security
- Reliability
- Troubleshooting
- Abuse prevention
- Fraud prevention
- Incident response
- Legal compliance
- Service operation
Examples of limited technical logs and security metadata may include IP address, device type, browser type, app version, timestamps, request metadata, authentication events, error details, and security events.
8. Encryption and Transport Security
Patravo uses secure connections to protect data in transit between users, apps, browsers, and Patravo services.
Patravo uses infrastructure and storage providers that support safeguards for stored data, including encryption at rest where appropriate.
Patravo does not store full payment card numbers unless expressly disclosed. Payment card processing, where used, is handled by payment processors such as Stripe, Apple, Google, or another payment provider.
Encryption is an important safeguard, but it is not the only safeguard. Patravo also uses access controls, authentication, logging, monitoring, vendor review, and operational procedures to protect the service.
9. Authentication and Account Protection
Patravo uses Clerk for authentication and account management.
Authentication-related safeguards may include:
- Secure login flows
- Account identifiers
- Session management
- Authentication event tracking
- Account recovery processes
- Clerk Client Trust signals and session controls where available
- Planned multi-factor authentication requirements for organization administrators
- Support for third-party login providers where enabled
- Role-based access after login
Patravo does not currently require two-factor authentication for all organization administrators in the MVP, but Patravo plans to require multi-factor authentication for organization administrators.
Users are responsible for protecting their passwords, email accounts, devices, and authentication methods.
Organizations should promptly remove or change access for users who leave the organization, change roles, lose authority, or no longer need access.
10. Role-Based Access Controls
Patravo uses role-based access controls to help organizations manage who can see and do different things.
Access may depend on:
- Organization role
- Administrative permissions
- Adult or youth status
- Parent or guardian relationship
- Group membership
- Patrol, den, team, committee, or subgroup membership
- Event participation
- Public or private workspace status
- Organization settings
- Youth-protection settings
Roles may include, depending on product configuration:
- Youth members
- Parents and guardians
- Adult leaders
- Volunteers
- Organization administrators
- Organization owners
- Council, district, or chartered organization representatives
- Public website visitors
- Patravo support or operations personnel with authorized access
Organizations are responsible for assigning roles carefully and reviewing permissions regularly.
Patravo may restrict access during suspected compromise, authority disputes, legal requests, safety concerns, or security incidents.
11. Administrator Security
Administrator accounts can access sensitive organization settings and information. Patravo treats administrator security as especially important.
Patravo does not currently require two-factor authentication for all organization administrators in the MVP. Patravo plans to require multi-factor authentication for organization administrators.
Organizations should limit administrator roles to trusted and authorized adults or representatives.
Administrators should:
- Use strong passwords.
- Protect their second factor.
- Avoid shared accounts.
- Review user access.
- Remove former users promptly.
- Use secure devices.
- Avoid exporting data to insecure locations.
- Review public-sharing settings.
- Report suspected compromise quickly.
Patravo may suspend or restrict administrator accounts that appear compromised, unsafe, unauthorized, or in violation of Patravo policies.
12. Internal Access by Patravo
Patravo limits internal access to production systems and customer information.
Internal access is intended to be limited to authorized personnel and service providers who need access for legitimate purposes, such as:
- Operating the service
- Providing support
- Investigating security issues
- Troubleshooting reliability problems
- Responding to legal requests
- Preventing abuse
- Protecting youth safety
- Maintaining infrastructure
- Complying with law
Patravo follows least-privilege principles where appropriate. This means internal access should be limited to what is needed for the person, role, or service to perform an authorized function.
Patravo personnel and contractors with access to sensitive information should be subject to confidentiality obligations.
13. Files, Photos, Videos, and Media Storage
Patravo uses Cloudflare R2 for file and media storage.
Private files and media are stored in private Cloudflare R2 storage and accessed through signed URLs or other controlled access methods.
Media intentionally published publicly may be stored or served separately from private organization media, including through a special bucket, public storage path, or other separation method.
Examples of files and media may include:
- Photos
- Videos
- Attachments
- Thumbnails
- Event files
- Organization documents
- Public website media
- Captions and related metadata
Organizations are responsible for deciding what media to upload, who may access it, and what may be published publicly.
Youth photos, videos, names, identifying details, event participation, or sensitive information should be published publicly only with appropriate permission and in accordance with organization policy and applicable law.
Patravo cannot control screenshots, downloads, search-engine caches, social-media sharing, third-party archives, or copies made after content is intentionally published publicly or downloaded by an authorized user.
14. Email Security
Patravo uses Resend for email delivery.
Patravo does not use email open tracking or click tracking.
Email providers may process limited information needed to deliver service messages, such as:
- Email addresses
- Message content
- Delivery metadata
- Bounce or failure information
- Opt-out status
Patravo may send service-related communications, such as:
- Account notices
- Security notices
- Event reminders
- Organization announcements
- Safety notices
- Support responses
- Billing notices
- Policy notices
Email and push notifications are useful, but they are not perfect. Patravo does not guarantee that every email, push notification, or other message will be delivered, received, opened, read, or acted upon.
Patravo should not be used as the only method for urgent, emergency, or time-critical safety communications.
15. Logging, Monitoring, and Auditability
Patravo may log and monitor technical and security activity to operate, protect, and improve the service.
Logs may help Patravo:
- Detect suspicious activity
- Investigate account compromise
- Troubleshoot errors
- Improve reliability
- Prevent abuse
- Respond to security incidents
- Support auditability
- Comply with legal obligations
- Protect youth and vulnerable users
Logs may include limited technical and security metadata such as:
- IP address
- Device type
- Browser
- Operating system
- App version
- Timestamps
- Authentication events
- Permission changes
- Administrative events
- Request metadata
- Error details
- Security events
Patravo designs logs to avoid storing customer content, youth roster details, message contents, media contents, and other unnecessary personal information.
Logs are retained for a limited period based on operational, security, legal, and safety needs. Logs may be preserved longer when needed for safety, legal compliance, security investigations, abuse prevention, or dispute resolution.
Logs are not used for advertising.
16. Secure Software Development
Patravo uses secure software development practices designed to reduce risk before features reach users.
These practices may include:
- Security review during product design
- Youth-safety review for youth-facing features
- Code review
- Dependency management
- Secure configuration
- Secret management
- Testing
- Vulnerability review
- Secure deployment practices
- Production change controls where appropriate
- Separation of development and production environments where appropriate
- Review of access-control changes
- Review of public-sharing features
- Review of youth, guardian, and administrator workflows
Patravo prioritizes security issues based on severity, exploitability, affected users, affected data, and potential youth-safety impact.
17. Vulnerability Management
Patravo works to identify, review, prioritize, and remediate security vulnerabilities.
Vulnerability management may include:
- Monitoring dependencies
- Applying security updates
- Reviewing security reports
- Investigating suspected vulnerabilities
- Prioritizing fixes based on risk
- Applying emergency patches when needed
- Reviewing changes that affect authentication, permissions, public sharing, media, messaging, or youth-safety controls
Patravo considers youth-safety impact when prioritizing vulnerabilities. A vulnerability that affects youth information, guardian relationships, private messages, files, photos, videos, administrative access, or public sharing may receive higher priority.
18. Responsible Disclosure
Patravo welcomes good-faith security reports.
Security reports should be sent to:
Security researchers should not:
- Access, modify, delete, or share user data.
- Access youth information.
- Download private files or media.
- Attempt social engineering.
- Send spam or phishing messages.
- Disrupt the service.
- Perform denial-of-service testing.
- Attempt physical attacks.
- Exfiltrate data.
- Publicly disclose a vulnerability before Patravo has had a reasonable opportunity to investigate and remediate it.
Patravo may publish a separate Responsible Disclosure Policy at:
https://patravo.com/trust/responsible-disclosure
That policy may provide more detail about safe-harbor expectations, reporting requirements, out-of-scope testing, and how Patravo reviews security reports.
19. Incident Response
Patravo maintains procedures for reviewing and responding to suspected security incidents.
A security incident may include:
- Unauthorized account access
- Compromised administrator account
- Unauthorized access to organization data
- Unauthorized public exposure of private content
- Vulnerability exploitation
- Misconfigured access controls
- Suspicious authentication activity
- Abuse of messaging or media features
- Vendor security issue
- Data loss or accidental deletion
- Unauthorized access to files, photos, videos, messages, or youth information
When Patravo investigates a suspected security incident, Patravo may:
- Review logs and security metadata
- Restrict accounts
- Require password resets
- Revoke sessions
- Disable features
- Restrict organization workspaces
- Preserve relevant records
- Remove or restrict content
- Contact affected organizations
- Contact affected users
- Contact service providers
- Contact app stores
- Contact law enforcement, regulators, child-safety authorities, or other appropriate parties when legally required or reasonably necessary
- Take steps to contain, remediate, and reduce recurrence
The timing and content of notifications depend on the facts, legal requirements, safety considerations, and the status of the investigation.
Patravo may delay or limit notice when required by law, when requested by law enforcement, when notice would increase risk, or when more information is needed to avoid misleading affected parties.
20. Backups and Recovery
Patravo maintains backup and recovery procedures to support service continuity and data recovery.
Backups may be used to:
- Recover from technical failures
- Restore service after outages
- Investigate incidents
- Support business continuity
- Protect against accidental data loss
Backups are protected through appropriate safeguards and retained for a limited period based on operational, legal, security, and recovery needs.
Deleted data may remain in backups until normal backup expiration and purge cycles are complete.
Backups are not a substitute for organization exports. Organizations should keep appropriate copies of critical event, emergency, legal, and recordkeeping information where needed.
Patravo does not guarantee that every deleted or lost item can be restored.
21. Vendor and Subprocessor Security
Patravo uses selected service providers to operate and secure the platform.
These providers support hosting, compute, database services, authentication, file and media storage, email delivery, and related infrastructure.
Patravo currently uses:
| Provider | Purpose | Data Processed |
|---|---|---|
| Vercel | Hosting, deployment, and compute | Web/app traffic, request metadata, technical logs, application responses |
| Convex | Database services and backend compute | Organization data, account-linked records, rosters, events, permissions, messages, settings, attendance, and related application data |
| Clerk | Authentication and account management | Names, emails, phone numbers where used, login identifiers, authentication events, sessions, account protection signals, account metadata |
| Cloudflare R2 | File and media storage | Uploaded files, photos, videos, attachments, thumbnails, storage metadata |
| Resend | Email delivery | Email addresses, email content, delivery metadata, bounce and failure information; open and click tracking disabled |
Service providers may process personal information only as needed to provide services to Patravo.
Patravo does not allow service providers to use Patravo data for their own advertising, marketing, data brokerage, or unrelated purposes.
Patravo’s current subprocessor list is available at:
https://patravo.com/trust/subprocessors
Some Patravo service providers may maintain their own security certifications, audits, or compliance reports. Those provider materials support Patravo’s vendor review, but they do not mean Patravo itself has the same certification unless Patravo separately states that it has completed that certification.
22. Hosting, Compute, and Database Services
Patravo uses Vercel for hosting, deployment, and compute.
Patravo uses Convex for database services and backend compute.
These services help Patravo run application logic, store organization data, deliver web and app experiences, and operate the platform.
Patravo configures and uses these services to support security, reliability, and privacy. Patravo is responsible for how it designs, configures, and operates Patravo on top of these providers.
23. Mobile App Security
Patravo provides iOS and Android apps.
Mobile app security depends on both Patravo and the user’s device environment.
Patravo’s mobile security practices may include:
- Secure app communication with Patravo services
- Platform permission controls
- Authentication through Clerk
- Push notification handling where enabled
- Session management
- App updates through official app stores
- Limiting mobile access based on account and organization permissions
Users should:
- Keep the Patravo app updated.
- Keep iOS or Android updated.
- Use device passcodes or biometric unlock where available.
- Avoid using compromised, jailbroken, or rooted devices for sensitive organization access.
- Protect notification previews if sensitive information may appear.
- Report lost or compromised devices when they may affect Patravo access.
If device-level biometric unlock is supported, biometric data is handled by the device platform and is not collected by Patravo.
Patravo does not collect precise GPS location unless a specific feature requires it, the feature is enabled, and the user grants permission.
24. Public Websites and Public Sharing
Patravo may support public websites or public pages for organizations.
Public pages are separate from private organization workspaces.
Organizations control what they publish publicly. Private organization content is not public by default.
Public content may be visible to anyone, indexed by search engines, shared by visitors, captured in screenshots, or cached by third parties.
Organizations should publish youth photos, youth names, identifying details, event information, or sensitive information only with appropriate permission and in accordance with organization policy and applicable law.
Patravo may provide controls to update or remove public content. Patravo cannot control screenshots, downloads, search-engine caches, social-media sharing, third-party archives, or copies made after content is intentionally made public.
25. Payment and Billing Security
If Patravo accepts payments, payment processing may be handled by payment providers such as Stripe, Apple, Google, or another payment processor.
Payment processors may process:
- Billing contact information
- Payment method details
- Subscription information
- Invoice information
- Transaction metadata
- Payment status
Patravo does not store full payment card numbers unless expressly disclosed.
Billing access should be limited to authorized organization representatives.
Payment processors have their own security practices, privacy policies, and terms.
26. Security and Privacy of Logs
Patravo’s logging practices are designed to support security and reliability while avoiding unnecessary exposure of sensitive information.
Patravo designs application logs to avoid storing:
- Customer content
- Youth roster details
- Message contents
- Media contents
- File contents
- Unnecessary personal information
Patravo may still process limited technical and security metadata, such as:
- IP address
- Device information
- Browser information
- App version
- Request metadata
- Error details
- Timestamps
- Authentication events
- Security events
- Administrative events
This information may be used for security, troubleshooting, reliability, abuse prevention, incident response, and legal compliance.
Patravo does not use logs for advertising.
27. Data Export, Deletion, and Security
Patravo supports organization data portability and responsible deletion.
Organizations may request export or deletion of organization data, subject to legal, safety, security, backup, billing, dispute-resolution, and legitimate recordkeeping limits.
Exported data may contain sensitive youth, family, volunteer, organization, event, media, or communication information. Organizations are responsible for protecting exported data after export.
Users and organizations should not store exported data in unsecured locations or share it with unauthorized people.
Deleted data may remain in backups for a limited period before being purged through normal backup cycles.
Some records may be retained when needed for safety, audit, legal, security, billing, dispute-resolution, or legitimate organization recordkeeping reasons.
28. Security Limitations
Patravo works to protect the service, but no system is 100% secure.
Patravo cannot guarantee that:
- The service will always be available.
- Every vulnerability will be prevented.
- Every unsafe action will be detected.
- Every account will remain secure.
- Every message will be delivered.
- Every notification will be received.
- Every report will be reviewed immediately.
- Every user will configure permissions correctly.
- Every organization will use youth-protection settings properly.
- Every third-party provider will operate without error.
- Every device, email account, carrier network, or browser will be secure.
Patravo cannot control:
- User devices
- User email accounts
- Phone carrier networks
- Browser extensions
- Screenshots
- Downloads by authorized users
- Third-party sharing after public publication
- Organization misuse
- Incorrect role assignments
- Unauthorized sharing by users
- External services not controlled by Patravo
Security requires responsible behavior by Patravo, organizations, administrators, parents, guardians, adult leaders, volunteers, and users.
29. Security for Councils, Chartered Organizations, and Related Organizations
Patravo may be used by multiple organizations that have different relationships to the same youth program.
For example, a local troop, pack, crew, ship, or post may be connected to a chartered organization, council, district, committee, national organization, camp, or other governing body.
Patravo may support these relationships through roles, permissions, linked organizations, reporting, exports, oversight tools, or administrative workflows.
Organizations are responsible for assigning access based on actual authority and applicable rules.
If there is a dispute about who controls an organization workspace, Patravo may require reasonable proof of authority. Patravo may temporarily restrict, preserve, suspend, or limit access while the issue is reviewed.
30. Security Reviews and Claim Verification
Patravo aims to verify public security claims before publishing them.
Security, privacy, youth-safety, app-store, and marketing claims should be reviewed against actual product behavior, provider configuration, and internal procedures.
Patravo may maintain an internal claim verification matrix to track:
- Public security claims
- Evidence supporting each claim
- Product behavior
- Responsible owner
- Review status
- Exceptions
- Approved public wording
- Recheck cadence
This helps Patravo avoid overpromising and keeps public documentation aligned with actual safeguards.
31. Reporting Security Concerns
Security concerns should be reported to:
Support questions should be sent to:
Privacy questions should be sent to:
When reporting a security issue, please include:
- A clear description of the issue
- Steps to reproduce, if safe and appropriate
- The affected URL, account, organization, or feature, if known
- Screenshots or logs, if they do not expose sensitive information
- Your contact information
- Whether you believe youth information, personal information, or organization data may be affected
Do not include sensitive youth information, private messages, passwords, full tokens, payment information, or private media in a security report unless Patravo specifically asks for it through a secure process.
If there is an emergency or immediate risk of harm, contact emergency services or the appropriate authorities first.
32. Updates, Versioning, and Changelog
Patravo is committed to transparent policy updates.
Every update to this Security Policy receives a version number.
Current and previous versions are available at:
https://patravo.com/trust/security/versions
Material changes are summarized in the changelog at:
https://patravo.com/trust/security/changelog
Patravo may announce material changes by email, in-app notice, website notice, or another reasonable method.
Patravo may avoid publishing sensitive operational details if doing so could increase security risk.
33. Contact
For security questions or reports:
Venlorin LLC
522 W Riverside Ave Ste N
Spokane, WA 99201
United States
Website: https://patravo.com
Security: security@patravo.com
Support: support@patravo.com
Privacy: privacy@patravo.com
For urgent safety concerns, contact emergency services or the appropriate authorities first.