Privacy & Operational Security Policy
Effective Date: August 9, 2026
1. Operations and Scope
Convalence Labs operates as an independent analytical laboratory based in Spain. This document outlines the technical protocols governing information management, data minimization, and infrastructure security across our digital platforms and verification ecosystems.
2. Information Ingestion and Purpose
Our systems are engineered to limit data collection strictly to what is necessary for functional performance.
- Inquiries: Information submitted through our communication interfaces is used solely to evaluate and respond to technical requests.
- Analytical Data: Metadata, sample parameters, and corporate identifiers provided during analysis requests are processed exclusively to generate, issue, and maintain laboratory certificates.
- Public Verification: Our public report validation ecosystem operates on an account-free architecture, eliminating the need for persistent user profiling or credential storage.
3. Data Lifecycle and Retention
Information is retained under strict schedules determined by operational utility and verification requirements:
- General communications are held only for the duration of the active operational loop required to fulfill the request.
- Core analytical records and certificate hashes are preserved within long-term archives to guarantee the permanent validity of the public verification service.
- We do not commercialize, rent, or distribute information to external third parties.
4. Technical Safeguards and Infrastructure
We deploy a multi-layered defensive framework to protect the integrity of our architecture:
- Perimeter Security: All traffic is routed through encrypted connections (HTTPS/TLS), with HTTP Strict Transport Security (HSTS) enforced site-wide to prevent downgrade or interception attempts.
- Origin Protection: Our server infrastructure only accepts connections originating from our content delivery and security provider's verified network ranges. Direct external access to the backend server is blocked at the firewall level.
- Automated Threat Screening: Public-facing entry points, including the verification portal, contact form, and administrative authentication, are protected by bot-detection screening and rate-limited access controls with escalating cooldown periods to deter automated abuse.
- Volatile Processing: Certificate generation and uploaded file payloads are handled within transient, volatile memory (RAM) and are not written to persistent disk storage during processing. Auxiliary metadata, including geolocation and device information embedded in submitted photographs, is automatically stripped prior to storage.
- Credential Storage: Authentication secrets and verification keys are stored exclusively as one-way cryptographic hashes. They are never stored or logged in plain, reversible form.
- Access Controls: Analytical repositories utilize strict Least-Privilege Policies (POLP), restricting system access to time-bounded, cryptographically signed tokens with limited storage scope.
- Communications Integrity: Outbound email communications are authenticated using SPF, DKIM, and DMARC protocols to reduce the risk of domain impersonation.
5. Institutional Contact
For technical inquiries regarding our analytical framework, certificate validation architecture, or operational security infrastructure, please contact our engineering department through the communication interface on our dedicated Contact page.