Security
Where your chatbot’s data lives, and who touches it.
This page is about Pivra for business, the chatbot on your website. It says what we do, and what we have not done yet. For the Pivra Desk app, see Pivra Desk security.
Last updated 8 October 2026.
Hosting
The application and database run in Sydney, Australia. Replies are generated in the United States.
| Application and API | Fly.io, Sydney region (syd) |
|---|---|
| Database, sign-in and file storage | Supabase, configured for the Sydney region (AWS ap-southeast-2) |
| Scanning of uploaded files | Our own scanner on Fly.io in Sydney, reachable only on Fly’s private network |
| Website and chat widget delivery | Vercel, served from its global edge network |
| Generating replies and embeddings | OpenAI’s API, which processes requests in the United States |
Our providers may give their own staff support access from outside Australia under their terms. What your visitors type, and the knowledge needed to answer, is sent to OpenAI for each reply.
Providers that process your data
These are the sub-processors for the chatbot, as listed in our privacy policy. We list a new or replacement provider here at least 30 days before it starts processing your data, except an emergency replacement needed for security or to keep the service running, which we list promptly.
| Provider | What it does | When |
|---|---|---|
| Vercel | Delivers the website, dashboard and chat widget | Always |
| Fly.io | Runs the application, API and upload scanner | Always |
| Supabase | Database, sign-in and file storage | Always |
| OpenAI | Generates chatbot replies and the embeddings used to search your knowledge | Always |
| Stripe | Payments. We never see or store full card numbers | Paid plans |
| Amazon SES | Sends account and notification email, and the email channel | Depending on the features you use |
| Twilio or Meta | SMS handover alerts and messaging channels such as WhatsApp | Only if you turn them on |
| Integrations you choose | Your CRM, calendar or job system, such as HubSpot or ServiceM8 | Only if you connect them |
| Google Analytics, Google Ads, Meta Pixel | Measure visits and ads on pivra.ai | Only after a visitor consents, and only on pivra.ai, not in your chat widget |
How it is protected
Encrypted in transit
The API only accepts HTTPS, and the website, dashboard and widget are served over HTTPS.
Encrypted at rest
The database and file storage are encrypted at rest by Supabase. On top of that, integration API keys, custom action headers and the access tokens for Messenger, Instagram and Slack are encrypted by the application with AES-256-GCM before they are stored; WhatsApp, Twilio and calendar tokens rely on the database encryption. Saved API keys and access tokens are never sent back to the dashboard or readable from the browser, and are used only to call the service they belong to.
Uploads are scanned before use
An uploaded file is quarantined until a ClamAV malware scan passes. If the scanner cannot be reached, the file stays quarantined and is never read.
Two-factor sign-in
Every account can turn on two-factor sign-in with an authenticator app (TOTP) in Settings, Security.
Workspace checks on every request
Requests are checked against your workspace on the server, and team roles decide who can change settings or billing.
We ask OpenAI not to store our requests
Our calls to OpenAI ask it not to store responses (
store: false). OpenAI says it does not train on API data unless the customer opts in, and it may keep requests for a limited time for abuse monitoring. We do not promise zero retention at OpenAI, because we have not verified that control for our account.
How long we keep it
Your chatbots, knowledge, conversations and leads are kept while your account is active, so the chatbot keeps working and you keep your history. Some logs, such as delivery logs and diagnostics, are kept for shorter periods.
An archived chatbot can be restored for 14 days. It is not deleted automatically after that; ask us and we will delete it.
When you close your account or ask us to delete data, we remove or de-identify it from our live systems, except where the law, tax, fraud prevention or a dispute requires us to keep it. Backups expire on our providers’ backup schedules rather than being edited one by one. Stripe keeps payment records under its own obligations.
The full wording is in section 7 of the privacy policy.
What we have not done yet
Larger buyers often ask for these. We would rather say so plainly than imply otherwise.
- No SOC 2 report. We have not started an audit.
- No ISO 27001 certificate.
- No independent penetration test.
- No public status page or uptime commitment yet.
- No EU or US data region. Data is hosted in Australia only, and replies are generated in the United States.
- No automatic deletion schedule. Data is kept while your account is active, and deleted when you ask or close your account (see below).
- No single sign-on (SSO) or audit log export.
A data processing agreement is available on request. Read our standard DPA and email support@pivra.ai to sign.
Report a security problem
Email support@pivra.ai with “Security” in the subject. Tell us what you found and how to reproduce it. Please do not access other people’s data or disrupt the service while testing. We will reply and keep you updated.