Security & Trust.
Your security, IT, and procurement teams verify claims before an AI chatbot touches customer conversations. So this page is written plainly: what is built and in production today, and what we deliver as part of an enterprise engagement or have on our roadmap. We will not blur that line.
Zurvo is an AI support chatbot for your website that answers from your approved content and hands off to your team when it can’t help. The same discipline runs through how we handle your data.
Security and controls available today.
These capabilities are live in the product and in use by customers now.
Multi-tenant data isolation.
Every organization’s data is logically isolated. Knowledge bases, conversations, business profiles, and analytics are scoped to your tenant, and access is enforced at the data layer so one customer’s content can never surface in another customer’s chatbot. Your approved knowledge powers your chatbot and only your chatbot.
Role-based access control (RBAC)
Team access is governed by roles. Administrators, agents, and other team members see only what their role permits — inbox, knowledge management, analytics, billing, and configuration are each gated. This lets you give frontline support staff the tools they need without exposing account-wide controls.
Audit logs
Sensitive actions are recorded. Audit logging gives your security and compliance teams a trail of who did what and when across the workspace, supporting internal reviews and incident investigation.
Encryption
Data is encrypted in transit and at rest. Connections use TLS, and stored data is encrypted using industry-standard algorithms. Payment details are handled by our PCI-compliant payment processor and never stored on our systems.
Human-in-the-loop oversight
This is a security and risk control, not just a feature. Zurvo’s chatbot answers from your approved knowledge and hands the customer to your team when it can’t answer from your content. When confidence is low or a human is needed, it hands off to your team’s inbox — with conversation context, AI-generated summaries, assignment, SLAs, canned replies, and internal notes. A human stays in control of edge cases, sensitive requests, and anything outside the chatbot’s approved scope.
LLM usage accounting.
Every model interaction is metered and attributed, giving you visibility into usage and cost at the organization level. This supports governance and budget oversight for AI spend.
Available for enterprise engagements / on our roadmap.
We are direct about what we have not yet built or certified. The items below are not in production today and are not independently certified. We frame them honestly so your security team can plan, and we deliver them as part of a scoped enterprise engagement or note them as roadmap. We will not represent these as existing certifications.
- SSO / SAML. Single sign-on via SAML and your identity provider is available for enterprise engagements. We will scope and implement it with your IT team.
- SOC 2. We are not SOC 2 certified today. We can discuss our security practices, share documentation, and align on a path as part of an enterprise relationship. We will not claim an attestation we do not hold.
- HIPAA / BAA. For healthcare engagements, a Business Associate Agreement and HIPAA-aligned handling are available to discuss as part of an enterprise engagement. This is not a current certification.
- Data residency. Region-specific data residency is available for enterprise engagements where your requirements demand it.
If a capability is not listed under “available today,” assume it requires an engagement to deliver — and ask us. We would rather lose a checkbox than misrepresent one.
How we work with your security team.
Bring your security questionnaire, your architecture review, and your procurement process. We will answer specifically, distinguish shipped from planned, and scope anything your environment requires. Most deployments go live in days, but never at the expense of an honest answer.
Try it live.
See how Zurvo answers from your own content and hands off to your team, and walk through our controls with your security team. Try it live and bring your hardest questions.