Security & Compliance

Built for conversations
that can’t leak.

ISO 27001-certified and SOC 2 Type II-audited infrastructure, UK GDPR, NHS DSPT compliance, PCI DSS-compliant payment handling, BYO-KMS, and UK or EU residency — implemented as runtime controls, not policy documents. The artifacts your security and compliance teams will actually want to read, on a service we run end to end for you.

ISO 27001
certified infrastructure
NHS DSPT
standards met
PCI DSS L1
compliant handling
UK GDPR + DPA 2018
ICO registered
SOC 2 Type II
audited infrastructure
Principles

Three commitments
everything else follows from.

Security at Convexa starts with three rules. Every control below is how we enforce them, and they are committed in writing in our data processing agreement.

01

Your data stays yours

We don’t train on your call audio, transcripts, or knowledge base content. It’s in every contract, and the runtime enforces it.

02

Least-privilege by default

Per-agent secrets, per-call scopes, and per-role access. The model never sees raw credentials. Our operators see only what their role permits, and every access is logged.

03

Reversible and auditable

Every action is recorded in a tamper-evident log. Every change is versioned. Every export is reproducible. The compliance trail is part of the service we run for you, not a quarterly project.

Controls inventory

Controls, verified
by independent auditors.

Control
What it does
Status
Encryption in transit
TLS 1.3 with modern ciphers between caller, carrier, and Convexa edge. SRTP for media streams.
ENFORCED
Encryption at rest
AES-256-GCM. Per-deployment KEKs. BYO-KMS via AWS KMS or GCP KMS on Enterprise.
ENFORCED
RBAC + SSO
SAML 2.0 with Okta, Google, Microsoft Entra. SCIM provisioning. Role-based scopes per agent and per deployment.
ENFORCED
PII / PHI redaction
Auto-redaction of SSN, card numbers, DOB, account numbers in transcripts and logs. Voice retained but masked in playback for unauthorized roles.
ENFORCED
Audit log
Tamper-evident write-once log of every config change, secret access, recording read, export. Streamable to your SIEM.
ENFORCED
Vulnerability mgmt
Continuous dependency scanning, plus regular external penetration testing by an independent firm.
ENFORCED
Tenant isolation
Logical isolation in shared infra; dedicated-tenant deployments on Enterprise Plus. No cross-tenant data flow at the runtime level.
ENFORCED
Model isolation
Your prompts, knowledge base, and call data are never used to train models — yours or anyone else's. Contractual and runtime guarantee.
ENFORCED
A call's data, traced end-to-end

Where the bytes go.
Where they don't.

For every conversation, this is the lifecycle — at rest, in transit, in scope, out of scope. It is the same handling we run for regulated work in healthcare and financial services.

01 · ON CALL

In flight

  • SRTP media · TLS 1.3 signaling
  • Per-call ephemeral session keys
  • Tokenized PAN capture if present
  • No raw audio retained outside region
02 · POST CALL

At rest

  • AES-256-GCM, per-deployment KEK
  • PII / PHI auto-redacted in transcripts
  • Retention per your policy
  • BYO-KMS on Enterprise
03 · ON ACCESS

In use

  • RBAC + SSO required
  • Audit log on every read
  • Watermarked exports
  • Right-to-delete actioned on request
Regional residency

Your data stays
where you need it.

Choose a region for each deployment. Convexa keeps recordings, transcripts, and derived data inside it — including for AI inference.

United Kingdom
eu-west-2 (London) · default
European Union
eu-west-1 (IE), eu-central-1 (DE)
United States
us-east-1, us-west-2
Australia
ap-southeast-2 (Sydney)
Canada
ca-central-1
Brazil
sa-east-1 · on request
Japan
ap-northeast-1 · on request
Dedicated
VPC-isolated · Enterprise Plus
Sub-processors

Every vendor who can
see anything.

Subscribe to changes
Sub-processorPurposeData accessedRegion
Amazon Web ServicesCloud hosting · object storageencrypted data at restUS · EU · UK · AU · CA
Google Cloud PlatformSecondary cloud · regional residencyencrypted data at restEU · UK · BR · JP
CloudflareEdge CDN, DDoS protectionrequest metadataglobal
TwilioCarrier-grade telephonycall metadata, signalingUS · EU
BandwidthUS PSTN terminationcall metadataUS
StripeCustomer billingbilling contact onlyUS · EU
DataDogInfra observabilitymetrics, error traces (no PII)US
PagerDutyInternal on-call paginginfra alerts onlyUS

Customers are notified by email 30 days before a new sub-processor is added.

Trust center artifacts

Documents your security
team will ask for.

Available on request through our trust center, under NDA — usually within 30 minutes. Infrastructure certifications are provided from our platform provider; service-level documents are our own.

SOC 2 Type II report
infrastructure · latest 12-month period
PDF · NDA
NHS DSPT toolkit
compliance evidence pack
PDF
PCI AoC
infrastructure · Level 1 service provider
PDF · NDA
DPA (GDPR + UK)
with SCC module 2
PDF
Architecture diagram
data flow + trust boundary
PDF · NDA
Latest pen-test summary
independent firm · quarterly
PDF · NDA
CAIQ Lite
Cloud Security Alliance v4
XLSX
Vendor security packet
pre-filled common questionnaires
ZIP · NDA
ISO 27001 statement
infrastructure · scoping & controls map
PDF
FAQ

Things everyone asks.

No. Your call audio, transcripts, prompts, and knowledge base content are never used to train Convexa or third-party models. This is a contractual guarantee on every plan and a runtime guarantee, not a request you have to opt into.
Built to scale,
human by design.

Talk to a security engineer who's been through your industry's audit.