Security and Control for AI Support.
Per-tenant data isolation, role-based access, audit logs, encryption, and layered defenses against prompt injection, CSRF, and SSRF — with an honest roadmap.
3-day free trial · Monthly or annual billing · Cancel anytime
What's true today
Per-tenant isolation and role-based access.
Every organization's data is scoped to its own tenant with row-level security at the database, and access is governed by roles so people do only what their role permits. This isolation is architectural, not a setting.
- Knowledge, conversations, and leads never shared across the platform
- Your content trains nothing outside your own account
- Owner, admin, agent, viewer, plus custom roles
Recorded and encrypted
Audit logs and encryption you can trace.
Sensitive actions are recorded, and customer data is encrypted in transit and at rest. Together with recorded conversations and their sources, you can trace not just who acted but what the chatbot answered and where it came from.
- Audit log: who did what, and when
- Webhook URLs and secrets encrypted at rest and masked on read
- Usage accounting surfaces AI cost, not an opaque bill
Layered defenses
Hardened against AI-specific attacks.
Zurvo hardens the AI and web attack surface, not just the perimeter — because a bot that reads your pages and documents is a target for injected instructions.
- Prompt-injection hardening: content sanitized, system prompt hardened
- SSRF protection on the crawler; CSRF protection on state changes
- Layered rate limiting across chat, crawl, ingestion, and lead capture
Enterprise engagements
Scoped per deal, not claimed as shipping.
These are not standard, self-serve, or certified features today. We support them as part of a managed enterprise engagement and will be straight about scope and timeline — never representing them as existing certifications.
- SSO / SAML can be scoped for an enterprise engagement
- Data-residency arrangements can be discussed for enterprise deployments
- Team access today is by role-based invitation
On the roadmap
Published before it's in place — on purpose.
Security teams find the gaps regardless, and a vendor who disclosed them upfront earns more trust than one who got caught. These are directions we're investing in, not capabilities we represent as live.
- SOC 2 attestation is a roadmap item, not a current certification
- HIPAA alignment and BAAs are roadmap considerations, not in place
- An accurate posture survives the review; an inflated one doesn't
We’re precise about what’s true.
Security reviews reward specifics that hold up under scrutiny, so this page draws a clear line between what Zurvo provides today, what we scope per enterprise engagement, and what’s on the roadmap. If a control isn’t built and certified, we won’t say it is. Because the chatbot answers only from your content and every conversation and source is recorded, you can trace what was said, where it came from, and who acted.
Security runs through the product, not beside it: isolation makes multi-org safe, roles decide who touches the inbox and the knowledge base, and recorded sources keep grounded answers auditable alongside your analytics. SSO/SAML, data residency, SOC 2, and HIPAA remain enterprise-engagement or roadmap items we won’t misrepresent as shipping. See pricing, and try it live to walk through what’s live, what we scope, and what’s on the roadmap, line by line.
Frequently asked questions.
Is my data isolated from other customers?
Yes. Every organization's data — knowledge, conversations, leads — is isolated to its own tenant with row-level security. Your content is scoped to your account, not shared across the platform, and it trains nothing outside your own deployment.
Is Zurvo SOC 2 or HIPAA certified?
No, and we won't claim otherwise. A formal SOC 2 attestation and HIPAA alignment are roadmap items, not current certifications. We draw a clear line between what's live today, what we scope per enterprise engagement, and what's on the roadmap.
How does Zurvo protect against AI-specific attacks?
Scraped and uploaded content is sanitized and the system prompt is hardened, so instructions hidden in a page or message can't hijack the bot. The crawler has SSRF defenses so it can't reach internal services, and the app has CSRF protection and layered rate limiting.
Can I see who did what?
Yes. Sensitive actions are recorded in an audit log — who did what, and when. Combined with recorded conversations and their sources, you can trace both team actions and what the chatbot answered and where it came from.
How are webhook secrets and integrations secured?
Webhook URLs and secrets — like a Slack notification webhook — are encrypted at rest and masked when read back, so a configured integration doesn't expose its credentials in the interface.
How exactly is per-tenant isolation enforced?
Every organization's data — knowledge, conversations, leads, and customer interactions — is scoped to your tenant and not shared across the platform, enforced with row-level security at the database. The isolation is architectural, not a setting, and it's what makes multi-organization safe: several businesses under one login, each fully separated, with your content training nothing outside your own account.
How does role-based access control work?
Access is governed by roles, so people see and do only what their role permits. Owner, admin, agent, and viewer roles get appropriate scopes, and owners can define custom roles on a permission matrix — who manages knowledge, who works the team inbox, who views analytics, and who administers the account. See Team and Roles. Team access today is by role-based invitation.
What are the layered application defenses?
Zurvo hardens the AI-specific and web attack surface, not just the perimeter. Scraped and uploaded content is sanitized before it reaches the model and the system prompt is hardened (prompt-injection hardening); the website crawler is defended against server-side request forgery so it can't reach internal services (SSRF protection); state-changing requests carry CSRF protection; and layered rate limiting spans chat, crawling, ingestion, and lead capture.
What about encryption and usage accounting?
Customer data is encrypted in transit and at rest within the platform. Sensitive configuration like webhook URLs and secrets is encrypted at rest and masked on read. Zurvo also tracks AI usage and cost, giving you visibility into consumption rather than an opaque bill, surfaced in your analytics and dashboard usage meters.
What about SSO, SAML, and data residency?
These are not standard, self-serve, or certified features today. Single sign-on and SAML-based identity integration can be scoped as part of a managed enterprise engagement, and specific regional data-residency arrangements can be discussed for enterprise deployments rather than assumed out of the box. We'll be straight about scope and timeline and won't represent them as existing certifications; team access today is by role-based invitation.
Why publish roadmap items you don't yet have?
A formal SOC 2 attestation and HIPAA alignment with Business Associate Agreements are roadmap considerations, not current certifications. We publish them because security teams find the gaps regardless, and a vendor who disclosed them upfront earns more trust than one who got caught. An accurate posture survives the review — an inflated one doesn't.
Turn your website into your best support agent.
Train Zurvo on your content, answer customers with citations, and hand off to your team when it counts.
3-day free trial · Monthly or annual billing · Cancel anytime