Skip to content

Security & data handling

Your deal data, protected.

Enterprise deals run on confidential conversations. We built Covisio so that yours stay inside a controlled environment, and improve only your own model.

  • Your data improves only your model

    Analysis specific to your company is held separately and never read across customers. We do not use customer information to train, fine-tune or improve any general-purpose or foundation model.

  • No external AI providers

    All model inference runs inside Covisio’s own Google Cloud tenant, on open-weight models we host or Google Cloud Vertex AI. Customer information is never sent to an outside AI provider or inference API.

  • Redacted on ingest

    Transcripts are automatically redacted as they enter our environment, and customer information is prohibited in non-production systems.

  • A person reviews every deliverable

    Our team reviews transcripts and AI output on a need-to-know basis, under access controls. Nothing reaches you without human review.

Our security program

Controls, not promises.

A designated Security Officer owns the program and reviews it at least annually. Full details are available to customers and prospective customers under NDA.

Request security details
  • Written information security program, consistent with the New York SHIELD Act
  • Encryption in transit and at rest; production database on private networking with no public endpoint
  • Least-privilege access with quarterly documented access reviews
  • Mandatory multi-factor authentication on every account
  • Production separated from development environments
  • Peer review before any code reaches production, with dependency, static-analysis and secrets scanning
  • Information classification with handling rules for each level
  • Vendor due diligence with annual reassessment
  • Security awareness training at onboarding and annually
  • Documented incident response with defined escalation and notification timeframes
NDA first
A non-disclosure agreement is signed before any deal data is shared with us.
Where data lives
Google Cloud, US East region; Google Workspace data region set to the United States. Region-restricted processing available where your agreement requires it.
How long we keep it
As set out in your agreement; otherwise returned and deleted within 90 days of the engagement ending, or on request.
Who processes it
A deliberately small set of subprocessors, published in full, with advance notice before any is added.

Read our Privacy Policy and Subprocessor List, or contact security@covisio.com.

Take control of your most critical pursuits

Stop leaving your most important deals to chance.

Partner with Covisio to bring machine attribution and veteran GTM advisory into your deal rooms this quarter.

Request a Strategic Deal Assessment

Prefer an executive briefing? Contact our founders directly at partners@covisio.com