Security & privacy

How Talvo protects your customers' data

What we do today, who processes your data, and what isn't available yet. If your review needs more, email us and we'll answer your questionnaire.

Your data

Encrypted in transit

Every page, API call, widget request and webhook is served over HTTPS.

Tenant isolation

Every query is scoped to the workspace it belongs to, on every endpoint. One customer's conversations are never readable from another workspace.

Operational data is pruned on a schedule

An hourly job clears failed sign-in attempts within about 15 minutes, visitor presence within a day, and webhook delivery logs after 30 days. Conversations stay until you delete them.

Self-serve deletion

Any user can delete their account from Settings or the mobile app. Deleting the last member of a workspace deletes the workspace and cancels its subscription.

Access

Four roles

Owner, admin, agent and viewer. Only owners and admins can change workspace settings, billing, keys and integrations.

Hashed credentials

Passwords are stored as salted hashes and API keys as one-way hashes. Neither can be read back, including by us.

Sign-in protection

Repeated failed sign-ins lock the account temporarily, and sensitive endpoints are rate-limited.

Audited support access

If Talvo support signs in to your workspace to help you, every change is recorded in your audit log under their name, and the session ends automatically after 60 minutes.

AI and integrations

Your content never trains our models

AI requests carry only the conversation and articles needed for the answer. You can turn AI off for a workspace in Settings.

Signed webhooks

Every outbound webhook carries an HMAC-SHA256 signature in X-Talvo-Signature, so your server can verify it came from Talvo.

Safe URL fetching

When Talvo crawls a help center or site you point it at, it resolves every address first and refuses private and internal networks, including after redirects.

No tracking cookies

One sign-in cookie, no advertising trackers, and page analytics that store nothing on the visitor's device. No consent banner needed.

Subprocessors

The companies that process data on our behalf, each only as far as needed to run Talvo. Which AI provider handles a request depends on the model your workspace selects.

ProviderPurpose
FlootApplication hosting, database and file storage
Amazon Web ServicesCloud infrastructure underlying our hosting, in the United States
OpenRouterRouting AI requests to the model providers below
OpenAI, Anthropic, Google, DeepSeekAI models behind auto-replies, drafts, summaries, translation and analysis
StripeSubscription billing and payment processing
EmailitSending and receiving support email
Google (Firebase Cloud Messaging)Push notifications to mobile devices

Not available yet

We'd rather tell you now than in the middle of a review.

  • A SOC 2 report
  • SAML single sign-on
  • A choice of data region (data is processed in the United States)

Security questionnaires and DPAs

Send us a message and choose "Security, privacy or a DPA". We'll answer your questionnaire and send a Data Processing Addendum with Standard Contractual Clauses to sign. To report a vulnerability, use the same form.

Read the full privacy policy and terms of service.