Security & Privacy
LiteSVR is local-first. You can use it without an account and without storing anything with LiteSVR. The application and the report travel together as one self-contained HTML file that lives in your normal project folder, SharePoint, OneDrive, document-management system, or other approved storage.
LiteSVR never stores a PDF. Your browser generates the client PDF at print time and saves it wherever you choose. No copy passes through LiteSVR under any storage option.
Licensing is separate from storage
LiteSVR is free for individual use, including at work. A firm that standardizes on LiteSVR needs an annual firm license. A firm license does not require Hosted Office Defaults or Cloud Projects.
Choose where reports are stored
Local or firm-managed storage is the default. Report text, images, comments, and history stay in the HTML file you chose. LiteSVR never receives that content. The file works with no internet access and no later synchronization, including on a network-isolated computer. PDF generation runs locally in the browser.
Your firm controls access, backup, retention, and deletion through its own storage system. Saved HTML reports contain the application's own JavaScript, so treat them as confidential, active project files.
Hosted Office Defaults are optional for licensed firms. An access-controlled workspace serves the current application with your approved branding, disclaimers, cover fields, and print settings. It stores member email addresses, authentication and audit records, office configuration history, and your office logo. It does not store report contents, report images, or report history unless you also enable Cloud Projects.
Cloud Projects are a separate, optional, workspace-wide storage feature. When enabled, report contents, assets, project information, and version history are stored in LiteSVR's Cloudflare-hosted data services. Every active member of the workspace can open every Cloud Project: there are no private projects and no project-level permissions. If you need narrower access, use local or firm-managed storage.
Cloudflare's managed data services encrypt stored data at rest and in transit. Stored report content has no public URL. Every request passes through the authenticated application.
Deletion and recovery
A Cloud Project moved to Trash stays recoverable for at least 30 days. There is no early permanent-delete or empty-Trash action. After that, scheduled maintenance removes the project, its versions, report contents, and assets, except assets still shared with a project you are keeping.
Audit records keep identifiers, event times, and the acting member. They never keep report contents.
Deletion removes data from LiteSVR's live storage. Cloudflare's D1 database also keeps 30 days of point-in-time history that cannot be switched off, so records can remain restorable by Cloudflare for up to 30 days after LiteSVR removes them — roughly 60 days from the day a project is moved to Trash. That history is not reachable through the application and is not offered as a backup service.
Export important Cloud Projects to your firm's record-retention system.
Security controls
- HTTPS with HSTS at the Cloudflare edge, six-month max-age, subdomains included
- Session cookies set
Secure,HttpOnly, andSameSite=Lax, scoped to the host - CSRF protection: state-changing requests must carry a matching
Originheader - Workspace membership is re-checked on every authenticated request, not only at sign-in
- Email sign-in codes with rate limiting and abuse protection
Content-Security-Policy,X-Frame-Options: DENY,Referrer-Policy: no-referrer,X-Content-Type-Options: nosniff, and a restrictivePermissions-Policy- HTML files downloaded from Cloud Projects are served with
connect-src 'none', so they cannot call out to any network - Cloudflare Access protects the private operator dashboard
- No third-party analytics, advertising trackers, or behavioural profiling
While you edit, LiteSVR may keep an automatic recovery draft in browser storage. It is cleared after a successful save. Firms with stricter workstation-cleanup rules should manage browser data through their normal IT procedures.
Current scope
LiteSVR is built for small, high-trust engineering and architecture offices. It does not provide SSO, SCIM, project-level roles, a country-specific data-residency commitment, or a formal uptime SLA. Email sign-in codes prove control of the approved mailbox. Turnstile is abuse protection, not a second authentication factor.
IT allowlisting
Allow HTTPS access to:
- litesvr.com
- www.litesvr.com
- app.litesvr.com
- challenges.cloudflare.com for Cloudflare Turnstile
Contact
For security questions, vulnerability reports, or requests concerning hosted workspace information: