We know architecture data can reveal how your systems work. This overview explains how ProvenMap handles that data in the hosted product, what customers control, and where our compliance work stands.
Browser sign-in, platform launch, and plugin access use separate credentials with separate scopes.
Your browser
Signs in with AWS Cognito
Portal
Accounts and billing
Agents and plugins
Scoped tokens
Platform
Architecture boards
AWS Cognito
AWS Cognito handles sign-in. Passwords do not pass through ProvenMap servers. Google and enterprise identity providers federate into the same user pool.
Short-lived RS256 token
Opening a workspace creates a signed token for that launch. The token expires in one hour, has no refresh token, and is verified by the platform using public keys.
Scoped access tokens
Plugins and agents use scoped access tokens. Repository credentials are tied to one board and branch. Personal agent tokens can be read-only or read-and-write.
ProvenMap plugins read repositories locally and send architecture metadata when a command is run. The repository itself is not uploaded.
Source excerpts are capped at about 500 characters and can be disabled with includeSourceReferences: false. Read the policy.
Plugin credentials, agent tokens, and integrations use the same token system.
Shown once
At creation, never again
Stored hashed
SHA-256, not the secret
Used and recorded
Last use, machine print
Expired or revoked
Effective next request
Customer data is separated by organisation, workspace, repository binding, and board access.
The tenant boundary
A body of architecture work
One repo, one board, one branch
The credential
Every level above must be named
A credential naming its binding, workspace and organisation is storable.
One with a gap in that chain is rejected by the database itself, not by a code review.
Single sign-on is available on the Team plan and above for organisations that want identity-provider enforcement.
The hosted product runs on AWS. Production infrastructure is defined in version-controlled infrastructure-as-code.
You can reconstruct important actions and request deletion through a defined process.
Request
You ask for deletion
30-day grace
Cancellable for the whole window
Purge issued
Instruction sent to the platform
Confirmed
The platform reports completion
If confirmation does not arrive within seven days, the request is flagged for an administrator rather than assumed complete.
The hosted product uses the subprocessors below. This list can be confirmed in a data processing agreement.
| Provider | Purpose | What it processes |
|---|---|---|
| Amazon Web Services | Hosting, databases, identity, storage | All hosted application and account data |
| Stripe | Payments and subscription billing | Billing contact and payment details |
| Resend | Transactional email delivery | Recipient address and message content |
| Sentry | Error and performance monitoring | Diagnostic and error context |
| Sanity | Marketing and documentation content | No customer data — published content only |
| OpenRouter | Language-model access, connected with your own account | Only what you send for analysis, under your own provider agreement |
| Kickbox | Email address verification at sign-up and on public forms | The email address being verified |
| Chatwoot | Website chat, loaded only with analytics consent | Chat messages and the details a visitor chooses to share |
| Cloudflare | Bot checks on public forms (Turnstile) | IP address and browser signals from the visitor’s browser |
Hosted infrastructure runs in AWS US East (N. Virginia). Regional residency is not available for hosted deployments. Self-hosting is available for strict residency requirements.
The items below reflect the current hosted product. Controls are stated as they exist today; certifications and external assessments are listed only after they are complete.
Report security issues by email rather than in a public issue. We will acknowledge the report and provide updates during investigation.
security@provenmap.comFor a questionnaire, DPA, or engineer-led walkthrough, contact us.
Contact usSyntaxia App Platform Ltd. Registered in England and Wales, company no. 15272701 Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom contact@provenmap.com