SECURITY
Security at Qevya
How we protect your business data and your clients' information.
Our approach to security
Security is not an afterthought at Qevya — it is built into every layer of the platform. We handle sensitive business data: client conversations, orders, invoices, and financial information. We treat that responsibility seriously.
Data storage and infrastructure
Your data is stored on servers located in Ireland (EU West, eu-west-1) within the European Economic Area, operated by Supabase on Amazon Web Services infrastructure. This location was chosen deliberately to ensure compliance with GDPR data residency requirements.
- All data is encrypted in transit using TLS 1.2 or higher
- All data is encrypted at rest using AES-256
- Database backups are encrypted and retained for 7 days
- Infrastructure is managed by Supabase, a SOC 2 Type II certified platform
Access control
Qevya uses row-level security (RLS) on every database table. This means each user can only ever read or write their own data — there is no administrative query or API call that can return another user's data without explicit permission. This is enforced at the database level, not just in application code.
Additional access controls:
- All authentication is handled by Supabase Auth with server-side token verification on every request
- Passwords are hashed using bcrypt — never stored in plain text, never transmitted after entry
- Session tokens are short-lived and rotated on every sign-in
- OAuth connections (Google Sign-in) use the PKCE flow with one-time authorization codes
AI and conversation data
Qevya uses Anthropic's Claude API to process your business conversations. This processing is governed by a data processing agreement between Pyntexia and Anthropic that explicitly prohibits Anthropic from using your conversation data to train their AI models.
Conversation content is processed transiently — it is sent to Anthropic's API for analysis and the response is returned. Raw conversation content is not stored by Anthropic beyond what is needed to complete the request.
Qevya never reads or stores your client conversations for any purpose other than providing you with the service. We do not sell conversation data, share it with advertisers, or use it to build profiles of your clients.
Responsible disclosure
If you discover a security vulnerability in Qevya, please report it to us at legal@qevya.com before disclosing it publicly. We take all security reports seriously and will respond within 48 hours. We do not currently offer a bug bounty programme but we will acknowledge responsible disclosures.
Contact
For any security-related questions, contact us at:
Pyntexia (Pty) Ltd
Email: legal@qevya.com
Website: qevya.com