Güven merkezi
Ne yaptık, ne yapıyoruz ve size ne borçluyuz
Güven bir pazarlama rozeti olmamalı. Aşağıda Convia'nın uyumluluk ve güvenlik çalışmalarının dürüst bir özeti var — üretimde canlı olanlar, devam edenler ve planlananlar.
Compliance programs
Programs we're running
- Live
GDPR readiness
Data Processing Agreement available on request. EU data residency for enterprise tenants. Per-tenant data deletion on demand.
- Live
Encryption at rest and in transit
TLS 1.2+ in transit, AES-256 at rest for primary databases, object storage, and backups.
- Live
Strict tenant isolation
Every request is ownership-checked at the application layer; no data shares across tenants.
- In progress
SOC 2 Type 1
In-progress with our auditor — letter of engagement signed, controls mapped, evidence collection underway. Expected within the next calendar quarter.
- Planned
SOC 2 Type 2
Planned after Type 1 lands. 6-month observation period.
- In progress
HIPAA BAAs
Available on enterprise plans for healthcare deployments. Custom configuration required — contact us via the Enterprise page.
- Planned
ISO 27001
On the roadmap. Likely after SOC 2 Type 2 completes.
Sub-processors
Convia uses a small set of vetted sub-processors to operate the platform. The current list is available in our DPA on request and is mirrored below.
- Hosting — managed cloud (region-elective on enterprise).
- LLM inference — frontier model providers (OpenAI, Anthropic). Customer content is not used for training.
- Voice — ElevenLabs for ConvAI text-to-speech and conversational voice.
- Messaging — Zernio (Meta Business Platform partner) for Instagram and WhatsApp.
- Billing — Lemon Squeezy (PCI handling).
- Transactional email — managed SMTP provider.
- Error monitoring — Sentry (no PII).
- File storage — encrypted object storage on the same hosting region as the primary database.
Need more detail?
Request a security pack — DPA, sub-processor list, architecture diagram, SOC 2 letter (when available), and answers to common procurement questions.