GDPR

● In effect

Customer data is stored in the EEA, including transactional-email data processed through Mailgun's EU infrastructure. Limited non-EEA access is protected by the EU–U.S. Data Privacy Framework or EU Standard Contractual Clauses, as applicable.

ISO 27001

● Targeted

Aligning controls with ISO/IEC 27001. Certification targeted for 2027.

Pen testing

● Planned

Independent penetration testing by an external firm, to be performed annually, targeted for 2027. The first test has not yet taken place; executive summaries will be available to customers under NDA.

Our approach

Klarivox holds two things together: customer conversations, and the CRM data those conversations are about. Both are sensitive. Our security model is designed around the assumption that an incident affecting Klarivox would be an incident for our customers — so we engineer to make that hard to cause, easy to detect, and bounded in blast radius if it ever happens.

  • Encrypt everything in transit and at rest. No production data crosses the network in plaintext.
  • Least privilege access. Access is granted by role and revoked automatically when people leave.
  • Logical tenant isolation. Each customer's data is logically separated, and access controls ensure workspaces can only reach their own data.
  • No model training on your data. AI providers operate under zero-retention terms; we don't train any Klarivox-owned model on customer data.
  • Notify within 72 hours. If a personal-data breach affects you, we notify you without undue delay and in any event within 72 hours of becoming aware.

Data protection

  • Encryption in transit: TLS 1.3 or higher for all network connections, including between internal services.
  • Encryption at rest: AES-256 at the storage layer on all customer data stores, backups, and object storage.
  • Data residency: Customer data is hosted by a European company inside the EU. Enterprise contracts may specify a different region by agreement.
  • Backups: Automated daily encrypted backups, multi-zone within region, retained for 90 days.
  • Deletion & portability: Customer data is exported or deleted on request, in a structured, commonly used format. On termination, data is deleted within 90 days; backup copies roll off on the standard cycle.

Access & identity

  • Mandatory MFA for all Klarivox employees and contractors accessing production systems.
  • Role-based access control (RBAC) on the principle of least privilege; access reviews to be conducted quarterly, targeted for 2027.
  • Automated deprovisioning on employee termination or role change.
  • Audit logs of authentication, access, and administrative actions, retained for 24 months and available on request.
  • No shared accounts for production access — every action is attributable to a named individual.

Infrastructure

  • Cloud provider: Hosted on UpCloud in an EU region; development and production environments are separated.
  • Network controls: Network access restricted to required ports and IP ranges; WAF and DDoS protection in front of public-facing services.
  • Tenant isolation: Workspace-level logical isolation enforced at the application and database layer; access controls prevent cross-tenant data access.

Application security

  • Automated security testing in CI: static analysis (SAST), secret scanning, dependency vulnerability checks.
  • Timely patching of known vulnerabilities; critical fixes prioritised against published SLAs.
  • Independent penetration testing by an external firm, to be performed annually, targeted for 2027; executive summaries will be available to customers under NDA once the first test is complete.
  • Bug bounty: Coordinated disclosure programme — see Report a vulnerability below.

AI & sub-processors

Klarivox uses large language models from a third-party provider (Mistral AI) to extract themes, sentiment, and signals from customer-uploaded conversations. The terms we operate under matter to your security review.

  • No training on your data. Our agreements with LLM providers include zero-retention terms — prompts and completions are not retained after the request is served, and are not used to train the providers' models.
  • No Klarivox-owned model training on customer data without express written consent.
  • Customer-data control of AI features: AI processing is invoked only as needed to serve specific product features; data is not sent to a model on a speculative basis.
  • Sub-processor inventory: We maintain a complete, current list of sub-processors at getklarivox.com/subprocessors, with 30 days' notice before direct changes and downstream notices passed on promptly.
  • International transfers use a valid GDPR Chapter V mechanism, including the EU–U.S. Data Privacy Framework or EU Standard Contractual Clauses, with supplementary measures where required.

Incident response

  • Tabletop exercises, to be conducted annually, targeted for 2027, to validate readiness and update playbooks.
  • Customer notification: If a personal-data breach affects you, we notify without undue delay and in any event within 72 hours of becoming aware, in accordance with our Data Processing Agreement and the GDPR.
  • Post-incident reports are shared with affected customers, including root cause and remediation.

People & process

  • Written confidentiality obligations for all employees and contractors with access to customer data.
  • Security and data-protection training, to be delivered annually, targeted for 2027, with role-specific training for engineering and customer-facing teams.
  • Vendor assessment before engaging any sub-processor that handles customer data, plus ongoing reviews.
  • Business continuity: BC/DR plans, to be documented and tested annually including data restoration drills, targeted for 2027.

Documents & resources

The following documents back up the commitments on this page and are the right place to point your privacy and security teams.

Report a vulnerability

If you believe you have found a security issue in Klarivox, please email us. We respond within one business day, will not pursue legal action against good-faith researchers, and will credit you in our disclosure log if you wish.

security@getklarivox.com