Security isn't a feature. It's the foundation.
Corviq is built on the assumption that your campaign data and client relationships are valuable and sensitive. Here's how we treat them that way.
Standards and certifications.
SOC 2 Type II — in progress
Formal third-party audit of our security controls, in progress with target completion alongside our public launch. Once complete, the SOC 2 report is available under NDA to enterprise customers.
PIPEDA-aligned
Canadian privacy law fully implemented in our data handling. Includes consent management, data subject rights, breach notification, and 72-hour incident response.
GDPR-aligned
European data protection standards implemented globally, not just for EU users. Subject access requests, deletion rights, and processor disclosures available to all customers.
CCPA-compliant
California consumer privacy rights honored for all customers. Right to know, right to delete, right to opt-out of sale (we don't sell data, but the right exists).
OWASP ASVS Level 2 aligned
Our security review process maps to OWASP Application Security Verification Standard Level 2. Code reviews check for ASVS controls before deployment.
How we protect your data.
Encryption in transit
TLS 1.3 minimum for all connections. Older TLS versions and HTTP are blocked at the edge. Certificate rotation via Cloudflare and Let's Encrypt.
Encryption at rest
AES-256-GCM for all stored data. Database encryption keys managed via Google Cloud KMS with envelope encryption.
Platform OAuth tokens
Stored using envelope encryption with separate, rotated KEK (key encryption key). Tokens never appear in logs, never transit unencrypted, never accessible to engineers without explicit access logging.
Multi-factor authentication
Required for all production access. Hardware-backed MFA preferred. No SMS-based 2FA permitted for engineer accounts.
Access logging
Every access to customer data is logged with engineer identity, timestamp, customer ID, and reason. Logs retained 12 months and reviewable on customer request.
Network isolation
Production runs in dedicated VPC with no public ingress except through Cloudflare. Internal services communicate via mTLS with service-to-service authentication.
Where your data lives.
- Primary storageGoogle Cloud Platform — northamerica-northeast1 (Montreal, Canada)
- Backup replicationGoogle Cloud Platform — northamerica-northeast2 (Toronto, Canada)
- Edge processingCloudflare's global edge network — no storage, only short-lived request processing
- Data transitEncrypted TLS 1.3 between all regions
Customer data does not leave Canada for storage purposes. Edge processing for performance happens globally but is encrypted and short-lived.
Operational security.
Security reviews
Every code change goes through automated security scanning (Snyk, GitHub Advanced Security) and manual review against an OWASP ASVS Level 2 checklist before merge.
Vulnerability response
Critical vulnerabilities patched within 24 hours. High-severity within 72 hours. Quarterly third-party security audits planned starting Q4 2026.
Incident response
72-hour breach notification to affected customers, per GDPR standards applied globally. Public post-incident reports for any incident affecting customer data.
Vendor security
All processors (Stripe, Cloudflare, Google Cloud, etc.) selected for SOC 2 or ISO 27001 compliance. Sub-processor list available on request.
What you can do.
- Use a strong unique password for your Corviq account (we enforce minimum 12 characters)
- Enable MFA when we ship it (planned Q4 2026)
- Use a work email, not personal
- Limit team member access to what each person actually needs
- Reach out to security@corviq.ai if you spot anything unusual
Found a vulnerability?
Email security@corviq.ai
Include details so we can reproduce. We monitor 24/7 once launched.
Encrypt sensitive findings
Use our PGP key — published at /security/pgp-key.txt after launch.
Don't publicly disclose
Give us a reasonable window to fix — 90 days, per industry standard.
We respect researchers
Proper attribution, no legal action for good-faith disclosure, bug bounty program coming post-launch.
For procurement teams.
Ready to put Corviq in front of your clients' data?
Start free trial →