How ConvoHut handles your customer data.
We prioritize the security and privacy of the information passing through our systems. Our infrastructure is designed with rigorous controls to ensure data integrity and confidentiality.
Certifications in progress.
This page states only what is currently implemented. We are actively working towards formal compliance frameworks and will update this document as audits are completed.
Data Storage
All persistent data is stored within secure cloud infrastructure hosted in the US-East region. We utilize continuous backup and multi-zone redundancy.
Access Control
Strict role-based access control (RBAC) limits internal access to customer data based on the principle of least privilege, requiring MFA for all administrative actions.
Encryption in Transit
All communications between our clients and servers, as well as internal service-to-service communication, are encrypted using TLS 1.2 or higher.
Customer Opt-in Handling
We provide granular APIs and webhooks for managing end-user consent records, ensuring explicit audit trails for all data collection events.
Data Deletion Requests
Automated pipelines support immediate soft-deletion upon API request, with hard deletion and cryptographic wiping completed within 30 days.
Subprocessors
We carefully vet all third-party vendors. A complete list of current subprocessors and their operational scope is maintained below.
Authorized Subprocessors
| Subprocessor | Purpose |
|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, data storage, and compute processing. |
| Cloudflare | Content delivery network (CDN), DDoS protection, and DNS resolution. |
| Stripe | Payment processing and billing management. |
| SendGrid | Transactional email delivery and notification routing. |
Security Enquiries
Have questions about our security practices, or need to report a vulnerability?
Where to next
Not ready to talk yet? These are the three things people usually look at before they are.