ConvoHut

How ConvoHut handles your customer data.

We prioritize the security and privacy of the information passing through our systems. Our infrastructure is designed with rigorous controls to ensure data integrity and confidentiality.

Certifications in progress.

This page states only what is currently implemented. We are actively working towards formal compliance frameworks and will update this document as audits are completed.

Data Storage

All persistent data is stored within secure cloud infrastructure hosted in the US-East region. We utilize continuous backup and multi-zone redundancy.

Access Control

Strict role-based access control (RBAC) limits internal access to customer data based on the principle of least privilege, requiring MFA for all administrative actions.

Encryption in Transit

All communications between our clients and servers, as well as internal service-to-service communication, are encrypted using TLS 1.2 or higher.

Customer Opt-in Handling

We provide granular APIs and webhooks for managing end-user consent records, ensuring explicit audit trails for all data collection events.

Data Deletion Requests

Automated pipelines support immediate soft-deletion upon API request, with hard deletion and cryptographic wiping completed within 30 days.

Subprocessors

We carefully vet all third-party vendors. A complete list of current subprocessors and their operational scope is maintained below.

Authorized Subprocessors

Subprocessor Purpose
Amazon Web Services (AWS) Cloud infrastructure, data storage, and compute processing.
Cloudflare Content delivery network (CDN), DDoS protection, and DNS resolution.
Stripe Payment processing and billing management.
SendGrid Transactional email delivery and notification routing.

Security Enquiries

Have questions about our security practices, or need to report a vulnerability?

Contact Security Team