Security FAQ
How is data encrypted?
All data transmitted to and from convobix is encrypted using TLS 1.3. Data at rest is encrypted using AES-256. Database backups are encrypted and stored in separate geographic regions. API keys and sensitive credentials are stored using one-way hashing.
Is convobix SOC 2 certified?
convobix is SOC 2 Type II compliant. Our latest audit report is available to Enterprise customers under NDA. Contact security@convobix.io to request a copy of our security documentation including our SOC 2 report, penetration test summaries, and security policies.
How often is penetration testing conducted?
We conduct annual third-party penetration tests across our entire infrastructure and application stack. We also run automated vulnerability scanning continuously. Critical vulnerabilities are patched within 24 hours; high-severity issues within 7 days.
What is your incident response process?
We maintain a 24/7 security operations function. In the event of a security incident affecting customer data, we will: contain the incident within 1 hour; notify affected customers within 72 hours; and provide a full incident report within 14 days. We are legally required to notify EU supervisory authorities within 72 hours of discovering a personal data breach.
Does convobix support multi-factor authentication?
Yes. We support TOTP-based MFA for all account types. Enterprise customers can enforce MFA across their organization and integrate with SSO providers (Okta, Azure AD, Google Workspace) via SAML 2.0. We strongly recommend enabling MFA on all accounts.