EOV6

Trust

Conservative notes for IT, compliance, and procurement teams.

Data handling

Data Storage & Retention Overview for IT teams.

Read the data handling overview

Security

  • Nonce-based CSP with a per-request nonce and no unsafe-inline in script-src.
  • Single CSP header from middleware as the policy source of truth.
  • Strict transport security (HSTS preload) with modern TLS in transit.
  • Security headers include XFO, XCTO, Referrer-Policy, and Permissions-Policy.
  • Temporary session model for in-call alignment with 6-digit code joins.
  • Designed for minimal collection during active session handling.

Consent and acknowledgements

Consent & Privacy Acknowledgement Flow for compliance teams.

Read the consent flow

Product scope

Procurement framing for how EOV6 complements existing systems.

Read the product scope

Contact

For procurement requests, security questionnaires, or controls detail, contact our team.

Contact EOV6