Trust
Security you can actually verify.
Customer Success is built on trust. The same goes for the platform you run it on. Here's how we protect your data and your customers' data.
Our approach
Security is a product feature, not a checkbox.
We're a small team building software for Customer Success leaders who handle sensitive customer data every day. Health scores, renewal notes, account plans, call transcripts. That data deserves the same care we'd want for our own.
We design around least privilege, encrypt everything in transit and at rest, and lean on cloud providers that already meet the highest bar (SOC 2, ISO 27001, GDPR). The goal is simple: security that works by default, not security that gets in your way.
Product security
Controls in the hands of your team.
The things admins and end users can rely on, every day.
Multi-factor authentication
MFA is available on every account and required for all Cohvia staff. We support TOTP authenticator apps with SSO on the roadmap for Enterprise plans.
Role-based access control
Granular roles let admins decide who can see customer data, edit playbooks, manage billing, or invite teammates. Permissions follow the principle of least privilege by default.
Password hygiene
Passwords are salted and hashed with bcrypt. We enforce length and complexity requirements and block known-breached credentials at sign-up.
Audit logging
Sensitive actions (logins, permission changes, exports, integrations) are logged so admins can review who did what and when.
Infrastructure & network
A foundation built on trusted providers.
We don't try to reinvent the parts of security that already work. We use proven infrastructure and harden it sensibly.
Encryption in transit and at rest
All traffic is served over TLS 1.2+. Customer data is encrypted at rest using AES-256 on managed cloud infrastructure.
Managed cloud hosting
Cohvia runs on tier-1 cloud providers (Vercel, Supabase) with SOC 2 and ISO 27001 attested data centers. See our subprocessors for the full list.
Backups and recovery
Automated daily backups with point-in-time recovery. We test restore procedures regularly so your data is recoverable when it matters.
Incident response
We maintain a documented incident response plan. Affected customers are notified without undue delay and, where required by GDPR, within 72 hours.
Privacy & compliance
GDPR-ready, with the paperwork to match.
We're based in a part of the world that takes privacy seriously, and we build like it.
GDPR compliance
We act as a processor under the GDPR. Customers can sign our Data Processing Agreement, exercise data subject rights, and request data export or deletion at any time.
Data Processing Agreement
A DPA is available to every customer on request and includes the EU Standard Contractual Clauses for international transfers.
Subprocessors
We publish the full list of subprocessors we rely on, what they process, and where. You'll be notified ahead of any material changes.
Working toward SOC 2
We follow SOC 2 Type II principles internally and plan to pursue formal certification as we scale. We're happy to walk current and prospective customers through our controls.
Report a vulnerability
If you believe you've found a security issue in Cohvia, we want to hear about it. Email us with a description and steps to reproduce, and we'll acknowledge within two business days. We don't pursue researchers acting in good faith.
security@cohvia.com