Trust

    Security you can actually verify.

    Customer Success is built on trust. The same goes for the platform you run it on. Here's how we protect your data and your customers' data.

    Our approach

    Security is a product feature, not a checkbox.

    We're a small team building software for Customer Success leaders who handle sensitive customer data every day. Health scores, renewal notes, account plans, call transcripts. That data deserves the same care we'd want for our own.

    We design around least privilege, encrypt everything in transit and at rest, and lean on cloud providers that already meet the highest bar (SOC 2, ISO 27001, GDPR). The goal is simple: security that works by default, not security that gets in your way.

    Product security

    Controls in the hands of your team.

    The things admins and end users can rely on, every day.

    Multi-factor authentication

    MFA is available on every account and required for all Cohvia staff. We support TOTP authenticator apps with SSO on the roadmap for Enterprise plans.

    Role-based access control

    Granular roles let admins decide who can see customer data, edit playbooks, manage billing, or invite teammates. Permissions follow the principle of least privilege by default.

    Password hygiene

    Passwords are salted and hashed with bcrypt. We enforce length and complexity requirements and block known-breached credentials at sign-up.

    Audit logging

    Sensitive actions (logins, permission changes, exports, integrations) are logged so admins can review who did what and when.

    Infrastructure & network

    A foundation built on trusted providers.

    We don't try to reinvent the parts of security that already work. We use proven infrastructure and harden it sensibly.

    Encryption in transit and at rest

    All traffic is served over TLS 1.2+. Customer data is encrypted at rest using AES-256 on managed cloud infrastructure.

    Managed cloud hosting

    Cohvia runs on tier-1 cloud providers (Vercel, Supabase) with SOC 2 and ISO 27001 attested data centers. See our subprocessors for the full list.

    Backups and recovery

    Automated daily backups with point-in-time recovery. We test restore procedures regularly so your data is recoverable when it matters.

    Incident response

    We maintain a documented incident response plan. Affected customers are notified without undue delay and, where required by GDPR, within 72 hours.

    Privacy & compliance

    GDPR-ready, with the paperwork to match.

    We're based in a part of the world that takes privacy seriously, and we build like it.

    GDPR compliance

    We act as a processor under the GDPR. Customers can sign our Data Processing Agreement, exercise data subject rights, and request data export or deletion at any time.

    Data Processing Agreement

    A DPA is available to every customer on request and includes the EU Standard Contractual Clauses for international transfers.

    Subprocessors

    We publish the full list of subprocessors we rely on, what they process, and where. You'll be notified ahead of any material changes.

    Working toward SOC 2

    We follow SOC 2 Type II principles internally and plan to pursue formal certification as we scale. We're happy to walk current and prospective customers through our controls.

    Report a vulnerability

    If you believe you've found a security issue in Cohvia, we want to hear about it. Email us with a description and steps to reproduce, and we'll acknowledge within two business days. We don't pursue researchers acting in good faith.

    security@cohvia.com

    Want a deeper look at our security posture?