Trust Center

Security, privacy, compliance, and data handling information

Compliance Overview

Current status and in‑progress programs

GDPR
Compliant
EU AI Act
Low Risk
ISO 27001
In Progress (Q1 2026)
SOC 2
In Progress (Q1 2026)
ISO 42001
TBD

Last updated: August 17, 2025

Overview

Convo is committed to protecting the security and privacy of our customers’ data. This Trust Center provides an overview of our security controls, compliance posture, data handling practices, and how to contact us for security and privacy matters.

Data Residency & GDPR

  • All customer data is stored and processed in Frankfurt (EU).
  • Encryption in transit (TLS 1.2+/1.3) and at rest is enforced.
  • We implement access controls and least-privilege principles for internal access.
  • We support data subject rights under GDPR. See our Privacy Policy.

EU AI Act

Our AI assists human users and does not autonomously make high-risk decisions. We assess our offering as low risk under the EU AI Act and monitor regulatory updates. We are not engaged in military or defense applications.

Certifications & Audits

  • ISO 27001: In Progress (target: Q1 2026).
  • SOC 2: In Progress (target: Q1 2026).
  • ISO 42001: TBD.
  • We will update this page as milestones are achieved.

Security Practices

  • Encryption: TLS 1.2+/1.3 in transit; encryption at rest.
  • Access Controls: SSO/MFA for staff, least privilege, role-based access.
  • Secure SDLC: code review, dependency scanning, environment separation.
  • Backups & DR: regular backups; RPO 24 hours, RTO 4–8 hours.
  • Monitoring & Alerting: proactive detection and response procedures.

Data Retention & Deletion

We retain customer data only for as long as necessary to provide the service and meet legal obligations. Upon request or contract termination, we delete or anonymize data in accordance with our retention policies.

Data Subject Rights (DSAR)

You may request access, correction, deletion, or portability of your data by emailing[email protected]. We aim to respond within 30 days in accordance with applicable laws.

Subprocessors

We engage the following subprocessors to deliver our services. We minimize the personal data shared with these providers and configure EU processing where available.

NamePurposeData CategoriesRegion / Notes
Google AnalyticsWeb analyticsUsage data, device/browser metadataConfigured for minimal data; EU processing where supported
OpenAIAI model inferencePrompt content as provided by usersWe minimize sent data; additional provider controls may apply
VercelFront-end hostingApplication content, logsEU/Frankfurt configuration where applicable
Fly.ioBack-end hostingApplication data and logsEU/Frankfurt configuration
ResendTransactional emailsEmail addresses, message metadataProvider regional processing policies apply
LiveKitInterviewing agent (realtime media)Audio/video session dataEU regions where available
GladiaTranscriptionAudio snippets for transcriptionEU processing where supported
AzureVideo/audio file storageMedia filesFrankfurt (EU) storage
SupabaseDatabase & user authenticationAccount data, application recordsEU/Frankfurt configuration

Incident Response

If you suspect a security incident affecting Convo or your data, email[email protected]. We triage promptly and will notify affected customers in accordance with applicable laws and contractual obligations.

Vulnerability Disclosure

We welcome responsible disclosure from security researchers. Please email[email protected]. We aim to acknowledge new reports within 3 business days.

Availability & Status

Our availability target is currently TBD. We will publish uptime targets and a public status page link here when available.

Contact & Requests

This page is provided for informational purposes and does not constitute legal advice. Please contact us for specific assurances required for your organization.