Security

Your customer data, handled with care

Sova processes the signals your customers leave across support, sales, and product channels. Here is how we handle that data, what we protect it with, and how to reach us if something looks wrong.

Practices

How we protect what you connect

A direct account of our data handling, encryption, access controls, and compliance posture. No vague assurances.

Data handling

Your data powers your decisions

The signals you connect to Sova are used to produce decisions for your workspace and nothing else. Your data is not used to train shared models, third-party models, or any model we do not operate. Signals are processed in your workspace context and are never pooled across customers.

Encryption

Encrypted in transit and at rest

All data between your browser, your connected sources, and Sova's infrastructure travels over TLS 1.2 or higher. Data at rest is encrypted with AES-256. Keys are managed through our cloud provider's key management service and rotated on a regular schedule.

Access control

Scoped to your workspace

Workspaces are fully isolated. Members can only access the workspace they have been explicitly invited to. Roles follow a least-privilege model, with read, edit, and admin permissions granted individually. SSO and SAML are available on the Scale plan, with full audit logs covering all workspace actions.

Sub-processors

Model-agnostic, disclosed providers

Sova routes signal analysis across frontier and open language models based on task type, cost, and latency. Sub-processor categories include model providers for inference, cloud infrastructure for compute and storage, and payment processing. A current list of named sub-processors is available on request.

Compliance

An honest Pre-Seed posture

SOC 2 Type II audit is in progress. We are GDPR and CCPA aligned: purpose limitation, data minimization, and the right to request deletion or export. A Data Processing Agreement is available on request. HIPAA is not offered at this stage. Sova is not suitable for processing protected health information.

Retention and deletion

Clear retention, simple deletion

Ingested signals are retained for the duration of your active subscription plus a 90-day grace period. On account deletion, data is removed from live systems within 30 days and from backups within 90 days. Request a full workspace export at any time by writing to support@sovasignals.com.

Responsible disclosure

Found a vulnerability? Tell us first.

If you discover a security issue in Sova, please report it to security@sovasignals.com. We acknowledge all reports within one business day and aim to complete an initial assessment within five business days. We ask that you give us reasonable time to investigate and resolve the issue before any public disclosure. We do not take action against researchers acting in good faith.

For the full legal picture, read our Privacy Policy and Terms of Service.

Start turning customer signal into decisions

Connect one source free and see your first ranked decisions with the evidence behind them. No credit card.