Skip to content

Security

Where your chatbot’s data lives, and who touches it.

This page is about Pivra for business, the chatbot on your website. It says what we do, and what we have not done yet. For the Pivra Desk app, see Pivra Desk security.

Last updated 8 October 2026.

Hosting

The application and database run in Sydney, Australia. Replies are generated in the United States.

Application and APIFly.io, Sydney region (syd)
Database, sign-in and file storageSupabase, configured for the Sydney region (AWS ap-southeast-2)
Scanning of uploaded filesOur own scanner on Fly.io in Sydney, reachable only on Fly’s private network
Website and chat widget deliveryVercel, served from its global edge network
Generating replies and embeddingsOpenAI’s API, which processes requests in the United States

Our providers may give their own staff support access from outside Australia under their terms. What your visitors type, and the knowledge needed to answer, is sent to OpenAI for each reply.

Providers that process your data

These are the sub-processors for the chatbot, as listed in our privacy policy. We list a new or replacement provider here at least 30 days before it starts processing your data, except an emergency replacement needed for security or to keep the service running, which we list promptly.

ProviderWhat it doesWhen
VercelDelivers the website, dashboard and chat widgetAlways
Fly.ioRuns the application, API and upload scannerAlways
SupabaseDatabase, sign-in and file storageAlways
OpenAIGenerates chatbot replies and the embeddings used to search your knowledgeAlways
StripePayments. We never see or store full card numbersPaid plans
Amazon SESSends account and notification email, and the email channelDepending on the features you use
Twilio or MetaSMS handover alerts and messaging channels such as WhatsAppOnly if you turn them on
Integrations you chooseYour CRM, calendar or job system, such as HubSpot or ServiceM8Only if you connect them
Google Analytics, Google Ads, Meta PixelMeasure visits and ads on pivra.aiOnly after a visitor consents, and only on pivra.ai, not in your chat widget

How it is protected

  • Encrypted in transit

    The API only accepts HTTPS, and the website, dashboard and widget are served over HTTPS.

  • Encrypted at rest

    The database and file storage are encrypted at rest by Supabase. On top of that, integration API keys, custom action headers and the access tokens for Messenger, Instagram and Slack are encrypted by the application with AES-256-GCM before they are stored; WhatsApp, Twilio and calendar tokens rely on the database encryption. Saved API keys and access tokens are never sent back to the dashboard or readable from the browser, and are used only to call the service they belong to.

  • Uploads are scanned before use

    An uploaded file is quarantined until a ClamAV malware scan passes. If the scanner cannot be reached, the file stays quarantined and is never read.

  • Two-factor sign-in

    Every account can turn on two-factor sign-in with an authenticator app (TOTP) in Settings, Security.

  • Workspace checks on every request

    Requests are checked against your workspace on the server, and team roles decide who can change settings or billing.

  • We ask OpenAI not to store our requests

    Our calls to OpenAI ask it not to store responses (store: false). OpenAI says it does not train on API data unless the customer opts in, and it may keep requests for a limited time for abuse monitoring. We do not promise zero retention at OpenAI, because we have not verified that control for our account.

How long we keep it

Your chatbots, knowledge, conversations and leads are kept while your account is active, so the chatbot keeps working and you keep your history. Some logs, such as delivery logs and diagnostics, are kept for shorter periods.

An archived chatbot can be restored for 14 days. It is not deleted automatically after that; ask us and we will delete it.

When you close your account or ask us to delete data, we remove or de-identify it from our live systems, except where the law, tax, fraud prevention or a dispute requires us to keep it. Backups expire on our providers’ backup schedules rather than being edited one by one. Stripe keeps payment records under its own obligations.

The full wording is in section 7 of the privacy policy.

What we have not done yet

Larger buyers often ask for these. We would rather say so plainly than imply otherwise.

  • No SOC 2 report. We have not started an audit.
  • No ISO 27001 certificate.
  • No independent penetration test.
  • No public status page or uptime commitment yet.
  • No EU or US data region. Data is hosted in Australia only, and replies are generated in the United States.
  • No automatic deletion schedule. Data is kept while your account is active, and deleted when you ask or close your account (see below).
  • No single sign-on (SSO) or audit log export.

A data processing agreement is available on request. Read our standard DPA and email support@pivra.ai to sign.

Report a security problem

Email support@pivra.ai with “Security” in the subject. Tell us what you found and how to reproduce it. Please do not access other people’s data or disrupt the service while testing. We will reply and keep you updated.