Security

Security isn't a feature. It's the foundation.

Corviq is built on the assumption that your campaign data and client relationships are valuable and sensitive. Here's how we treat them that way.

Compliance

Standards and certifications.

SOC 2 Type II — in progress

Target Q3 2026

Formal third-party audit of our security controls, in progress with target completion alongside our public launch. Once complete, the SOC 2 report is available under NDA to enterprise customers.

PIPEDA-aligned

Canadian law

Canadian privacy law fully implemented in our data handling. Includes consent management, data subject rights, breach notification, and 72-hour incident response.

GDPR-aligned

European standard

European data protection standards implemented globally, not just for EU users. Subject access requests, deletion rights, and processor disclosures available to all customers.

CCPA-compliant

California rights

California consumer privacy rights honored for all customers. Right to know, right to delete, right to opt-out of sale (we don't sell data, but the right exists).

OWASP ASVS Level 2 aligned

Code-review standard

Our security review process maps to OWASP Application Security Verification Standard Level 2. Code reviews check for ASVS controls before deployment.

Protection

How we protect your data.

Encryption in transit

TLS 1.3 minimum for all connections. Older TLS versions and HTTP are blocked at the edge. Certificate rotation via Cloudflare and Let's Encrypt.

Encryption at rest

AES-256-GCM for all stored data. Database encryption keys managed via Google Cloud KMS with envelope encryption.

Platform OAuth tokens

Stored using envelope encryption with separate, rotated KEK (key encryption key). Tokens never appear in logs, never transit unencrypted, never accessible to engineers without explicit access logging.

Multi-factor authentication

Required for all production access. Hardware-backed MFA preferred. No SMS-based 2FA permitted for engineer accounts.

Access logging

Every access to customer data is logged with engineer identity, timestamp, customer ID, and reason. Logs retained 12 months and reviewable on customer request.

Network isolation

Production runs in dedicated VPC with no public ingress except through Cloudflare. Internal services communicate via mTLS with service-to-service authentication.

Residency

Where your data lives.

  • Primary storage
    Google Cloud Platform — northamerica-northeast1 (Montreal, Canada)
  • Backup replication
    Google Cloud Platform — northamerica-northeast2 (Toronto, Canada)
  • Edge processing
    Cloudflare's global edge network — no storage, only short-lived request processing
  • Data transit
    Encrypted TLS 1.3 between all regions

Customer data does not leave Canada for storage purposes. Edge processing for performance happens globally but is encrypted and short-lived.

Operations

Operational security.

Security reviews

Every code change goes through automated security scanning (Snyk, GitHub Advanced Security) and manual review against an OWASP ASVS Level 2 checklist before merge.

Vulnerability response

Critical vulnerabilities patched within 24 hours. High-severity within 72 hours. Quarterly third-party security audits planned starting Q4 2026.

Incident response

72-hour breach notification to affected customers, per GDPR standards applied globally. Public post-incident reports for any incident affecting customer data.

Vendor security

All processors (Stripe, Cloudflare, Google Cloud, etc.) selected for SOC 2 or ISO 27001 compliance. Sub-processor list available on request.

Your part

What you can do.

  • Use a strong unique password for your Corviq account (we enforce minimum 12 characters)
  • Enable MFA when we ship it (planned Q4 2026)
  • Use a work email, not personal
  • Limit team member access to what each person actually needs
  • Reach out to security@corviq.ai if you spot anything unusual
Responsible disclosure

Found a vulnerability?

Email security@corviq.ai

Include details so we can reproduce. We monitor 24/7 once launched.

Encrypt sensitive findings

Use our PGP key — published at /security/pgp-key.txt after launch.

Don't publicly disclose

Give us a reasonable window to fix — 90 days, per industry standard.

We respect researchers

Proper attribution, no legal action for good-faith disclosure, bug bounty program coming post-launch.

Ready to put Corviq in front of your clients' data?

Start free trial →