Skip to content

Security

Security built into the architecture

How Convene separates customer data, protects projects on devices, handles untrusted input and keeps physical control safe.

Tenant isolation

A separate instance per organization

  • Each organization's Cloud instance runs in its own separate cloud project, with its own database, storage and users
  • Every project request is checked against the caller's project access (read or edit)
  • Projects can be password-protected; unlock tokens are short-lived and kept in memory only
  • Privileged account fields can only be changed through controlled flows, enforced by database rules

Local-first and offline

  • Convene Local and Convene Mobile keep each project as a Git repository on the device
  • Work continues offline; every change is a commit with full history
  • Sync refuses to overwrite cloud changes it has not seen, and keeps divergent work on its own branch
  • Local network sharing requires pinned HTTPS and Windows authentication
  • The Android app's embedded server listens only on the device itself

Device authorization and untrusted input

Device authorization

  • Desktop and tablet clients are authorized with a device code, not a stored password
  • Each request carries a device credential that can be revoked
  • Only defined record types can be sent through the evidence outbox

Untrusted files

  • Uploaded repositories and .cszip project files are treated as untrusted
  • Extraction is size-bounded and path-checked
  • Repository hooks, configuration and alternates are stripped
  • Repositories are cloned without symbolic links and integrity-checked
  • Uploaded Office templates are filled without running macros

Safety-gated vehicle control

Physical vehicle control runs only from Convene Local or Convene Mobile on the local network. It never runs through the cloud or the web application.

Gates before and during flight

  • Pairing with a single-use code, pinned TLS and a device identity
  • Three operator preflight acknowledgements before arming
  • Arming must be confirmed by the vehicle bridge and expires after a set time
  • Commands are signed, sequenced and expire after five seconds
  • A deadman stops manual input within a fraction of a second and releases authority after one second
  • An operator heartbeat releases control if the operator interface goes silent
  • Vehicle geofencing and return-to-home stay enabled, and the pilot's handheld controller can always override

This page describes architecture and controls. It is not a statement of certification or authorization. For your program's security requirements, contact us.

Questions about security?

We are glad to walk through the architecture with your security team.