Access Control Policy — SOVAI Technology LLC

Purpose

Define who may access SOV AI systems and customer data, and how that access is granted, used, and revoked.

Principle of Least Privilege

Every person and system component gets the minimum access needed to do its job. Access is granted for a specific need, not by default.

Account Types

Authentication

Authorization

Tenant isolation is enforced at the application layer: every query is scoped to the requesting user's organization. Customer files live in private storage buckets and are served only via short-lived signed URLs — never public links.

Privileged Access

Onboarding and Offboarding

Access Review

Periodically review who holds staff/admin accounts and production console access, and remove anything no longer needed.

Reporting

Report suspected unauthorized access, over-broad permissions, or any access-control concern to admin@sovaitech.com.