Information Security Policy

Last updated: July 6, 2026

Overview

AIVA Virtual Intelligence ("AIVA," "we," "us," or "our") is committed to protecting the confidentiality, integrity, and availability of client data and personal information processed through our AI employee platform. This Information Security Policy describes the administrative, technical, and physical safeguards we maintain to protect data across our voice, SMS, email, and workflow automation services.

Scope

This policy applies to all data processed through AIVA's platform, including client business information, contact databases, call recordings and transcripts, appointment and transaction data, and any personal information collected on behalf of our clients or their customers.

Data Encryption

  • Data in Transit: All data transmitted between AIVA's systems, our clients, and our third-party service providers is encrypted using industry-standard TLS 1.2 or higher.
  • Data at Rest: Personal information and client data stored within our infrastructure is encrypted at rest using AES-256 or equivalent encryption standards.
  • Voice Data: Call audio and transcripts are transmitted and processed over encrypted connections through our voice service providers.

Access Controls

  • Access to client data and production systems is restricted on a role-based, least-privilege basis. Only personnel who require access to perform their job function are granted it.
  • All administrative access to core systems requires unique login credentials. Shared credentials are not permitted for production systems.
  • Multi-factor authentication (MFA) is required for access to administrative dashboards, cloud infrastructure, and systems containing client data.
  • Access is reviewed periodically and revoked immediately upon a team member's departure or role change.

Third-Party Service Providers (Sub-Processors)

AIVA relies on the following categories of vetted, industry-standard sub-processors to deliver our services. Each is contractually and/or independently bound by its own security and compliance standards:

  • Voice & SMS Infrastructure: Twilio (SOC 2 Type II certified) for voice calling and SMS delivery.
  • Workflow Automation: n8n for orchestrating data flows between integrated systems, with encryption in transit between connected services.
  • Database & Backend: Supabase for structured data storage.
  • Application Hosting: Railway for application deployment and hosting.
  • AI Processing: OpenAI, Anthropic, and/or other AI service providers for natural language processing and conversational intelligence. Data sent to these providers is processed according to their respective privacy and security policies.
  • Payment Processing: Stripe (PCI-DSS compliant) for billing. AIVA does not store full credit card numbers.

AIVA does not sell client data to any third party, and sub-processors are used solely to deliver the contracted services.

Data Minimization & Retention

  • We collect and retain only the data necessary to provide our services. Personally identifiable information (PII) is retained only as long as needed for active service delivery or as required by law.
  • Clients may request deletion or export of their data. Standard data retrieval requests are honored within 30 days of a service cancellation, consistent with our Terms of Service.
  • Sensitive data, including Social Security numbers, financial account details, or health information encountered during transaction workflows, is handled with additional restricted access controls and is not retained longer than necessary for the specific transaction task.

Network & Infrastructure Security

  • Production systems are hosted on reputable cloud infrastructure providers that maintain independent security certifications.
  • Firewalls, network segmentation, and monitoring tools are used to detect and prevent unauthorized access to production environments.
  • Software dependencies and integrations are reviewed prior to deployment, and security-relevant updates are applied on an ongoing basis.

Incident Response

In the event of a suspected or confirmed data security incident involving client data, AIVA will:

  • Investigate and contain the incident as quickly as reasonably possible.
  • Notify affected clients without undue delay, and no later than required by applicable law, once the scope of the incident is understood.
  • Provide a summary of the incident, data affected, and remediation steps taken.
  • Cooperate with clients on any additional notification obligations they may have to their own customers or regulators.

Employee & Contractor Practices

  • All personnel and contractors with access to client data are required to follow this policy and are briefed on data handling practices appropriate to their role.
  • Work devices and accounts used to access client data are expected to use strong, unique passwords and MFA where available.

Compliance Alignment

AIVA's SMS and voice communication practices are designed to align with applicable regulations, including the Telephone Consumer Protection Act (TCPA) and CTIA messaging guidelines. Clients remain responsible for obtaining proper consent from their own customers, as outlined in our Terms of Service.

Changes to This Policy

We may update this Information Security Policy as our practices, infrastructure, or applicable regulations evolve. Material changes will be posted on this page with an updated "Last updated" date.

Contact Us

Questions about this Information Security Policy or a security concern can be directed to:

AIVA Virtual Intelligence

Atlanta, GA

Email: hello@aivavi.ai

Phone: (470) 486-6132