TRUST & SECURITY

Your AI data, treated like production data.

Obsivara sees your workflows, your costs, and your credentials. That is a responsibility we engineer for — here is exactly how.

Encryption

All customer data is encrypted with AES-256-GCM at rest and TLS 1.3 in transit. Integration credentials live in an isolated secrets vault with envelope encryption — never in logs, never in client responses.

Data retention

Telemetry is retained for 90 days by default, configurable per workspace. When the window elapses — or you delete a workspace — raw telemetry is permanently removed from primary stores.

Access

SSO via SAML, role-based access control, and full audit logs of every administrative action are available on Enterprise plans. Production access on our side follows least-privilege with hardware-backed MFA.

Infrastructure

Workspaces are logically isolated from one another end to end. Your telemetry is never used to train models made available to other customers — your data works only for you.

COMPLIANCE POSTURE
ON ROADMAP

SOC 2

SOC 2 is on our security roadmap. We're building our controls toward a formal audit — we're glad to walk prospective customers through our current security posture.

ALIGNED

GDPR

We build with GDPR principles in mind: we minimize the personal data we process and honor EU data-subject access and deletion requests. Reach out for data-processing questions.

ALIGNED

CCPA

We support access and deletion requests for California residents, and we do not sell or share personal information as defined by CCPA/CPRA.

SECURITY PRACTICES
01Least-privilege access to production, reviewed quarterly, hardware-backed MFA required
02Integration credentials encrypted with AES-256-GCM in an isolated secrets vault
03No prompt bodies stored by default — payload capture is opt-in and redactable per integration
04We keep a vetted list of subprocessors and notify customers before adding new ones
05Coordinated disclosure policy — report vulnerabilities to security@obsivara.com

Questions our docs don't answer? Ask us directly.

Security questionnaires, DPA requests, subprocessor lists, audit reports under NDA — our team turns them around fast.

Contact security team