Your data. Your rules.
Our controls.
iVaak is built for enterprise clients that can't afford to guess about where their data lives. Here's how we protect it — top to bottom.
Certifications & standards
Q3 target — auditor engaged
DPA available on request
Business Associate Agreement available for healthcare clients
Following SOC 2 Type 1
How we protect your data
Every tenant table in our Postgres has a policy pinning reads/writes to the authenticated user. RLS enforced at the database, not just the app.
When we integrate with your operational database, we use a dedicated user with the minimum grants — SELECT on named tables, UPDATE on named columns only. No DROP, DELETE, or ALTER surface.
Every mid-call tool webhook and every post-call outcome webhook carries an HMAC signature we verify before mutating state. Prevents spoofing.
iVaak talks to your database from a single, static production IP. Clients whitelist that one address on their firewall — no wildcard ranges.
Call recordings, transcripts, and knowledge documents encrypted at rest in managed object storage. TLS in transit end-to-end.
Every call, every tool invocation, every outcome write-back logged with request ID, timestamp, and actor. Retention configurable per SOW.
Client-specific tabs gated by email allowlists. One tenant never sees another tenant's calls, agents, or outcomes — enforced at both UI and DB layers.
You can export every row of your call metadata, every recording, every transcript at any time. No lock-in. Your EHR/CRM schema stays authoritative.
Need our DPA, sub-processor list,
or a security questionnaire?
We ship them as part of every enterprise engagement. Ask and you'll get them within one business day.
Request security documents