OLANVIR Back to OLANVIROpen app

OLANVIR security

Your keys stay private and under your control.

OLANVIR uses provider authorization screens whenever possible. If a service requires a reusable API key or bot token, OLANVIR clearly asks before keeping an encrypted copy in its hosted credential vault and lets the signed-in customer replace or remove it.

Hosted credential vault

When a provider requires a reusable key or token, OLANVIR keeps an encrypted copy in its hosted vault so scheduled work can run while your device is off. It is not stored on the business owner’s personal computer.

Encrypted before it is saved

OLANVIR encrypts supported credentials with AES-256-GCM before writing them to persistent cloud storage. The separate vault key is not stored with the encrypted record or returned to the browser.

Account-scoped access

Connection reads, updates, and removals require a signed-in user and are limited on the server to that user’s own records.

Rate limits and audit events

Verification attempts are rate-limited. Security events record the action and result without recording the credential value.

Clear boundaries

What OLANVIR does—and does not do.

Good security includes honest limits. No online service can promise zero risk, and OLANVIR does not claim certifications or controls it has not earned.

Provider authorization firstInstagram and YouTube use the provider’s approval screen. OLANVIR never asks for those account passwords.
API keys only when requiredServices such as ClickBank and Telegram may require a reusable key or bot token so syncing and alerts can continue while the customer’s device is off.
Secrets stay out of account viewsThe dashboard receives connection status and dates, never the stored credential value.
Least-privilege ClickBank accessOLANVIR asks for read access used to verify account and earnings data, not order, ticket, subscription, or payout write access.
You can remove OLANVIR’s copyDisconnect deletes the encrypted vault record from your OLANVIR account. It does not revoke the original key at the provider.

Keep your provider account secure too.

  1. 1Grant only the permissions OLANVIR requests.Do not use a broader administrative key.
  2. 2Review connected keys every 90 days.Replace a key sooner if a teammate leaves or you suspect exposure.
  3. 3Revoke at the provider when access should end.Removing OLANVIR’s encrypted copy cannot deactivate the original provider key.

Have a security concern?

Use the Help Center so the issue can be tied to your signed-in OLANVIR account without placing a credential in the message.

Open Help Center