/// SECURITY

What protects your data, and who can see it.

No certification badge we do not hold. Here are the mechanisms actually in place, the providers your data passes through, and what we cannot yet claim.

/// IN PLACE

What runs today.

Every point below matches code that is written and covered by tests. We will walk you through the detail on request.

SEPARATION

One client never sees another’s data

  • Every query is filtered by organisation at the model level, not at the screen
  • Twelve dedicated test suites check that one organisation can read nothing of another
  • API tokens carry their organisation: the isolation is structural, not vigilant
ACCOUNTS

Getting into your workspace

  • Passwords: twelve characters minimum, letters and numbers
  • A password found in a known breach is refused — checked by k-anonymity, the password never leaves the server
  • Two-factor by authenticator app, with single-use recovery codes
  • Six sign-in attempts per minute per address, then a temporary lock
  • The session is regenerated on sign-in, on sign-out, and on any change of identity
SECRETS

Your keys and your tokens

  • WhatsApp tokens, shop keys, Slack token, Airtable token, webhook secrets and the two-factor secret: encrypted at rest
  • A dedicated test checks that no secret ever appears in the logs
  • API keys you create are shown once: we keep only a fingerprint
OUTBOUND

What the product fetches from outside

  • Every address you give us — webhook, folder, shop — is checked before each call: no internal address, no redirect into the private network
  • The check is repeated on every send, not only when you save it
  • Our outgoing webhooks are signed with HMAC-SHA256, timestamped, and the signature is valid for five minutes
TRACEABILITY

What goes into the log

  • Every sensitive action is logged: who, what, when, on which organisation
  • Every request carries a correlation id, set before anything else
  • Support entering your workspace regenerates the session at both ends, refuses any staff account, and leaves a trace
/// YOUR RIGHTS

Take your data back, or erase all of it.

Both are done from your settings, with no email to write and no waiting period.

Export

You request an archive of your personal data from your settings. It is built in the background, downloadable from your account, and deleted automatically once its retention runs out.

Deletion

You retype your organisation’s name to confirm. The account is marked for erasure and purged seven days later — a scheduled task does it every night. You can cancel during those seven days.

Data processing agreement

The DPA is available on request, and its public version is online. It names the sub-processors below.

/// SUB-PROCESSORS

Who your data passes through, and what for.

The page this one replaces claimed “no customer data leaves the European Union”. That was false, and it is the kind of claim that gets paid for in a contract annex. Here is the real list. The last four are only involved if you connect the matching integration.

Provider
What it processes
Region
Status
Hostinger
Hosting of the service and the database: everything you put in it lives there.
United Kingdom
Required
OpenAI
The text of the conversation, for as long as it takes to produce the answer. No model training on your data.
United States
Required
Resend
Your transactional email: password resets, invitations, alerts, the daily recap.
United States
Required
Firecrawl
Your site address, and the content of the public pages it reads for your knowledge base.
United States
Required
Stripe
Your subscription and billing. Your card number never passes through our servers — it is entered on theirs.
United States and Ireland
Required
Meta (WhatsApp)
The messages exchanged on your WhatsApp Business number.
United States
If you enable it
Slack
Escalation alerts sent to your channel.
United States
If you enable it
Google Drive
The documents you designate as a knowledge source, read-only.
United States
If you enable it
Airtable
The tables you designate as a knowledge source, read-only.
United States
If you enable it

Each is covered by the European Commission’s standard contractual clauses. If your industry forbids transfers outside the EU, raise it before you sign: on some of these, a European alternative exists.

/// NOT YET

What we cannot claim today.

Written here rather than in a footnote. A security page is worth what it refuses to promise.

The host’s certifications

The host is Hostinger International Ltd, in a datacenter located in the United Kingdom, a country covered by a European Commission adequacy decision: that is what our legal notice states, and the legal notice is the binding one. The page this one replaces named a DIFFERENT host — three French cities, a datacenter tier, an HDS certification, DDoS protection and 24/7 monitoring. The site was naming two different hosts one click apart. We keep the name and the region, which are contractual; we do not keep the certifications, which we have not verified ourselves.

ISO 27001 certification

Convosia is not certified as an organisation, and we do not display the badge. A host’s certification is the host’s certification.

An uptime commitment

We have signed no contractual availability figure. The old page’s “99.99% guaranteed” rested on nothing.

A compliance question before you sign?

The DPA, the sub-processor list, the detail of any mechanism: ask, and we answer with files rather than badges.