Talvo holds your customers' conversations, so here is plainly how that data is kept.
Tenant isolation
Every workspace's data is separated at the database boundary. Conversations, contacts, articles and settings are scoped to a workspace id on every query, so one workspace cannot read another's data — including through the public widget and API surfaces, which resolve a workspace from its public app id and are constrained to it.
Encryption in transit
All traffic — the app, the messenger widget, the REST API and webhooks — is served over TLS.
Roles and permissions
Membership is role-based:
- Owner — full access, including billing and removing members. A workspace always keeps at least one owner.
- Admin — can change workspace settings, automation, API keys and webhooks.
- Agent — works the inbox and the knowledge base, without access to workspace-level settings.
- Viewer — read-only.
The audit log
Changes to settings, team membership, API keys, webhooks and billing are recorded in an audit log you can read in Settings → Activity, so you can see who changed what and when.
API keys and webhooks
API keys are shown once, at creation, and stored only as a hash — we cannot show you an existing key again, so treat the value you copy as the only copy. Keys can be revoked at any time. Outgoing webhooks are signed with an HMAC-SHA256 signature in the X-Talvo-Signature header so your endpoint can verify a request genuinely came from us.
Where AI processing happens
The AI agent reads your published knowledge-base articles and the conversation it is answering. It is not trained on your data — your content is used to answer your customers' questions, not to improve a shared model.
Something look wrong?
If you believe you have found a security issue, contact us directly rather than filing it on the public feedback board.
