Security at Olive
Effective Date: June 23, 2025
Last Updated: August 31, 2026
Olive protects personal and entrusted information through controls that are specific to the function, identity, authority, and record involved. This page describes controls currently established in the Olive architecture; it does not promise that any security system is infallible.
Important: Olive is not a medical, clinical, or emergency service. If you or someone you know is in immediate danger, call your local emergency number. See our Crisis Resources.
1. Governing security model
- Server-authoritative identity and authority. Account type, administrative authority, Founder authority, ownership, recipient rights, and relationship context are determined by protected server-side records and functions, not by browser metadata, email allowlists, subscription state, or relationship labels.
- Least privilege. Privileged background workers use independently scoped server-only credentials. A credential for one worker cannot authorize another worker.
- Fail-closed boundaries. Missing, incorrect, cross-worker, or unauthorized credentials are rejected. Provider failure does not grant access.
- Constitutional Vault controls. Entrusted Originals, directives, provenance, delivery, opening, deletion, and recovery follow the OLIVE Trust Charter and governing Vault architecture.
2. Data protection
- Encryption in transit. Public Olive application and service traffic is delivered over HTTPS/TLS by the hosting and service providers.
- Encryption at rest. Olive relies on provider-managed encryption at rest for hosted database, object-storage, and platform data.
- Access controls. Database row-level security, ownership checks, recipient and delivery rules, server-authoritative roles, and function-specific authorization constrain access. Being authenticated does not itself authorize access to another person's matter.
- Entrusted Original integrity. Canonical integrity records and provenance protect Entrusted Originals from silent replacement. Delivery and opening remain separate factual events.
- Data minimization. Olive limits collection and processing to information reasonably necessary for authentication, security, integrity, fulfillment, delivery, authorized product functions, and lawful operations.
Encryption reduces risk but does not eliminate it. Olive does not describe provider-managed encryption as end-to-end encryption unless a specific feature separately establishes that property.
3. Authentication and privileged access
Authentication is provided through Supabase Auth. Authorization remains separate from authentication.
- Founder and administrative capabilities use server-authoritative profile and designation records.
- No client or self-service path may assign Founder authority.
- Browser state, local storage, user-controlled metadata, and development role overrides are not authoritative security boundaries.
- Server credentials, service-role credentials, provider secrets, Airtable credentials, and dedicated worker credentials must not be shipped to the browser.
- Airtable operations use an authenticated server-side boundary rather than direct browser authentication to Airtable.
Olive does not publicly claim that every provider console or administrative surface enforces SSO, device trust, or a particular MFA configuration unless that control has been independently verified for the stated surface.
4. Application and service controls
- Origin enforcement. Sensitive server boundaries validate approved application origins where the boundary is designed for browser invocation.
- Rate limiting. The Airtable Whisper boundary uses shared server-side rate-limit state. This is a scoped control and is not represented as universal rate limiting across every Olive endpoint.
- Worker authorization. Reminder and Vault-delivery workers require dedicated credentials and reject missing, incorrect, or cross-worker authority.
- Atomic reminder fulfillment. Reminder fulfillment uses an atomic server-side operation so delivery state is not represented as complete before the governed action succeeds.
- Reminder lifecycle protection. Current reminder lifecycle operations are protected and legacy duplicate reminder runtime has been retired.
- Recovery controls. Vault recovery and Founder continuity mechanisms are fail-closed, narrowly callable, and preserve provenance. Recovery is not ordinary browser or user self-service authority.
5. AI processing and safety
Olive's AI companion may generate supportive prompts or responses when an authorized product function invokes an AI provider.
- AI is not a clinician and does not provide medical, legal, psychiatric, or emergency services.
- Vault AI processing requires function-specific authorization where the governing Vault architecture requires it.
- Inputs may be sent to the configured AI provider only for the authorized function.
- Olive presents crisis resources where appropriate, but does not promise that automated systems will identify every harmful, crisis, or self-harm expression.
- Olive does not claim that all content is filtered before storage.
- Olive does not infer a Child's or Teen's emotional state, wishes, relationship preference, or safety concern from non-engagement.
Users should not rely on Olive or its AI for emergency monitoring or outreach.
6. Child and Teen protections
Before age 13, a Child does not independently operate Olive or independently submit personal information or content through the Child account. Authorized guardian or facilitator assistance does not transfer ownership, confer recipientship, or reveal future-undelivered matter.
Teen protections include privacy-protective defaults, data minimization, no sale of Teen personal information, no behavioral advertising to Teens, no monetization of Teen Vault contents, no unnecessary engagement surveillance, no unnecessary public discoverability, and restricted unsolicited contact from unknown adults.
Olive is not a public people directory or open social-discovery service. A relationship or connection does not itself grant administrative authority or Vault access.
7. Logging, audit, and monitoring scope
Olive preserves designated security, authority, provenance, delivery, recovery, and lifecycle events where the governing architecture requires them. Not every user interaction or provider-console action is represented as an Olive audit event.
Integrity checks are used for protected Vault matter and source-governance assertions. Olive does not claim universal real-time security monitoring, automated anomaly alerting, or periodic review of every privileged action unless a specific control is independently established.
8. Retention, deletion, and recovery
Retention and deletion depend on the record's authority and obligations. Ordinary personal content, Entrusted Originals, recipient-held matter, provenance, delivery history, shared rights, legal holds, minimum security records, and historical attribution may have different treatment.
Only an Adult may initiate permanent deletion of their own identity or account. Child or Teen withdrawal is not permanent deletion. Account deletion does not authorize falsifying another person's legitimate surviving history or altering an Entrusted Original.
Recovery mechanisms are intended to restore protected continuity after a verified failure; they are not a promise that every record can always be recovered from every failure.
9. Incident response and legal obligations
Olive investigates reported security issues and will make notifications required by applicable law. Legal constraints are applied as narrowly as practicable while preserving unaffected protections and provenance. Olive does not adjudicate family disputes.
10. Responsible disclosure
To report a suspected security vulnerability:
- Email security@oliveforus.com.
- Provide a clear description and reproducible steps without including credentials or another person's private data.
- Do not access data that does not belong to you or disrupt the service.
11. Contact
- Security: security@oliveforus.com
- Privacy: privacy@oliveforus.com
- Support: support@oliveforus.com
This document will be updated when validated controls or providers materially change. The OLIVE Trust Charter remains the governing public trust commitment.