Trust & Security

How we handle your production data

Converra is designed for production environments. That means security and data handling aren't afterthoughts—they're foundational.

Data Minimization

We only process what's needed for optimization. Converra generates scenario abstractions from interaction patterns—not verbatim transcripts.

  • You control what data you send
  • Optional redaction before ingestion
  • No cross-customer training

Offline-First Architecture

By default, prompt testing happens in offline simulations—not on live users. Changes are validated against scenario abstractions derived from production patterns before anything ships.

Encryption Everywhere

Data is encrypted in transit (TLS) and at rest. All API communication uses HTTPS. We operate on reputable cloud providers and follow security best practices.

Production-Grade Infrastructure

Hosted on vendors that maintain SOC 2 Type II reports. We enforce strict tenant isolation and access controls to keep customer data separated. Enterprise deployments can support single-tenant and VPC requirements.

Data Retention

Retention is configurable. Data is deleted on request or within 30 days of account termination.

Full Audit Trail

Every optimization decision is logged: what changed, why it was proposed, who approved it, and when it shipped. Complete traceability for compliance and debugging.

What we don't do

We don't sell your data or use it to train models for other customers.

We don't run experiments on live users—simulations happen offline.

We don't require access to your entire production system—only the data you choose to send.

We don't make irreversible changes—every deployment includes instant rollback capability.

Security FAQ

Do you store raw transcripts?

We store conversation data you send for optimization. You control what's included—sensitive fields can be redacted before ingestion.

Do you train on our data?

No. Your data is used only for your optimization. We don't train shared models or use your data to improve other customers' prompts.

Where is data stored?

Currently US regions. Enterprise customers can request specific region deployments.

Can we self-host, use VPC, or set custom retention?

Yes—enterprise deployments support VPC, custom retention policies, and dedicated infrastructure. Contact us to discuss requirements.

Enterprise requirements?

For teams with specific security, compliance, or deployment requirements—including VPC deployment, custom retention policies, or security questionnaires—reach out and we'll work with you directly.

Contact security@converra.ai