Security & trust
DAVRO handles sensitive financial and carrier data on behalf of every customer. It's built so that isolation, encryption, and least-privilege aren't features bolted on — they're the architecture.
Row-level security enforces separation at the database, not in application code. One customer's data can never be reached from another's context — there is no shared pool and no co-mingling.
Traffic is served over TLS, and stored data is encrypted at rest. Sensitive material stays protected across its whole lifecycle.
Credentials and keys live in a managed secrets store — never in plaintext, never written to logs. Response bodies that could carry financial data are kept out of logs by design.
Each connection operates only within its own tenant context, and every user sees only what their role permits. Access is scoped from the authenticated session, not inferred.
The assistant, contained by design
DAVRO's conversational assistant is deliberately caged. It reads; it doesn't act on its own authority. And the data boundary is never the model's judgment — it's enforced beneath it.
Compliance posture
We'd rather tell you exactly where things stand than imply more. For vendor security reviews, we provide named sub-processors — including our accounting-connectivity provider — and complete your platform's security review as part of onboarding.
SOC 2 Type I gap analysis complete; formal audit not yet initiated.
Named sub-processors available for your vendor review on request.
Send it over. We'll work through your vendor review and walk your team through the architecture in detail.