How Talvo protects your customers' data
What we do today, who processes your data, and what isn't available yet. If your review needs more, email us and we'll answer your questionnaire.
Your data
Encrypted in transit
Every page, API call, widget request and webhook is served over HTTPS.
Tenant isolation
Every query is scoped to the workspace it belongs to, on every endpoint. One customer's conversations are never readable from another workspace.
Operational data is pruned on a schedule
An hourly job clears failed sign-in attempts within about 15 minutes, visitor presence within a day, and webhook delivery logs after 30 days. Conversations stay until you delete them.
Self-serve deletion
Any user can delete their account from Settings or the mobile app. Deleting the last member of a workspace deletes the workspace and cancels its subscription.
Access
Four roles
Owner, admin, agent and viewer. Only owners and admins can change workspace settings, billing, keys and integrations.
Hashed credentials
Passwords are stored as salted hashes and API keys as one-way hashes. Neither can be read back, including by us.
Sign-in protection
Repeated failed sign-ins lock the account temporarily, and sensitive endpoints are rate-limited.
Audited support access
If Talvo support signs in to your workspace to help you, every change is recorded in your audit log under their name, and the session ends automatically after 60 minutes.
AI and integrations
Your content never trains our models
AI requests carry only the conversation and articles needed for the answer. You can turn AI off for a workspace in Settings.
Signed webhooks
Every outbound webhook carries an HMAC-SHA256 signature in X-Talvo-Signature, so your server can verify it came from Talvo.
Safe URL fetching
When Talvo crawls a help center or site you point it at, it resolves every address first and refuses private and internal networks, including after redirects.
No tracking cookies
One sign-in cookie, no advertising trackers, and page analytics that store nothing on the visitor's device. No consent banner needed.
Subprocessors
The companies that process data on our behalf, each only as far as needed to run Talvo. Which AI provider handles a request depends on the model your workspace selects.
| Provider | Purpose |
|---|---|
| Floot | Application hosting, database and file storage |
| Amazon Web Services | Cloud infrastructure underlying our hosting, in the United States |
| OpenRouter | Routing AI requests to the model providers below |
| OpenAI, Anthropic, Google, DeepSeek | AI models behind auto-replies, drafts, summaries, translation and analysis |
| Stripe | Subscription billing and payment processing |
| Emailit | Sending and receiving support email |
| Google (Firebase Cloud Messaging) | Push notifications to mobile devices |
Not available yet
We'd rather tell you now than in the middle of a review.
- A SOC 2 report
- SAML single sign-on
- A choice of data region (data is processed in the United States)
Security questionnaires and DPAs
Send us a message and choose "Security, privacy or a DPA". We'll answer your questionnaire and send a Data Processing Addendum with Standard Contractual Clauses to sign. To report a vulnerability, use the same form.
Read the full privacy policy and terms of service.
