Honest status

Compliance status

Your vault encrypts on your device first. Formal compliance programs will follow when they are real and ready.

Coming later

HIPAA

We are not HIPAA certified and do not offer a BAA. Eirvr is invitation-only Alpha, not a covered-entity or business-associate offering.

Coming later

GDPR

We design for data minimization (ciphertext in the vault), but we are not advertising a completed GDPR certification or a standard DPA package.

Not started

SOC 2

No SOC 2 engagement is in progress and we are not publishing a completion date. That work belongs on a later wave, not this Alpha.

What we actually hold

Encryption is not immunity

Vault contents
Client-side AES-GCM means we cannot read file plaintext. That is the honest zero-knowledge claim.
Account metadata
Email, timestamps, and ciphertext blobs still exist on our side. We do not claim we have nothing to produce if lawfully required.
Payments
No Stripe trial is live on this Alpha. We are not advertising PCI processing or credit-card cancellation terms.