Security and permissions
How Nerava protects vehicle connections, partner access and the data that moves between them. This page lists controls that are in production today, not plans.
Transport
Every Nerava site and API is served over HTTPS. This website (neravanetwork.com) sends these response headers:
| Header | Value |
|---|---|
| Strict-Transport-Security | max-age=31536000 |
| X-Content-Type-Options | nosniff |
| X-Frame-Options | DENY |
| Referrer-Policy | strict-origin-when-cross-origin |
| Permissions-Policy | camera=(), microphone=(), geolocation=() |
| Content-Security-Policy-Report-Only | report-only: monitors scripts, connections and framing against Nerava origins without blocking them |
The Nerava API (api.nerava.network) sends Strict-Transport-Security for one year including subdomains, X-Content-Type-Options nosniff, X-Frame-Options DENY and a strict-origin referrer policy.
Partner access
- Partner API keys are stored only as SHA-256 hashes. A key can be revoked or rotated without changing the partner account.
- Partner Portal workspaces check membership and role before showing anything, and each workspace shows only that partner's own programs and results.
- Aggregate cohort reporting applies a minimum group size before showing results.
Vehicle authorization
- Vehicles connect through OAuth with Tesla Fleet API or Smartcar. Nerava never receives the vehicle owner's password.
- Drivers can disconnect a vehicle at any time. Disconnecting deactivates the connection; removing a vehicle also clears its stored OAuth tokens.
- Drivers grant and revoke partner data-sharing scopes separately from vehicle access.
Secrets
Production credentials live in AWS Secrets Manager and runtime configuration, not in application source. The repository has a pre-commit hook configured to block credential-shaped strings.
Certifications
Nerava has not completed a SOC 2 audit or any other security certification, and does not claim to. Our privacy practices are described in the Privacy Policy.
Report a vulnerability
Email security@nerava.network with details and, if you can, steps to reproduce. Please give us reasonable time to fix an issue before disclosing it.