Data Security

Last Updated: August 18, 2026

Last updated: August 23, 2026

The short version

  • Everything is encrypted, in transit and at rest. That includes your knowledge base, your customers' conversations, and any API keys you add.
  • We don't train on your data. Not your knowledge base, not your Agent conversations, not the outputs.
  • We don't sell your data. Ever, to anyone.
  • Every model runs through official APIs. No resellers, no unofficial endpoints, no workarounds.
  • Our infrastructure runs on SOC 2 certified cloud providers, hosted in the United States and the European Union.
  • Internal access to production is restricted and logged.
  • You can delete it. Your Agents, your knowledge base, your conversation history, your account.

1. What we're protecting

Nivon holds three kinds of data that matter most:

Your knowledge base. The documents, URLs, and content you upload to train a Agent.

Your customers' conversations. The messages your Agents exchange with your end users, and the responses generated for them.

Your credentials and keys. Your account login, and any provider API keys you add through BYOK.

Account and billing data is covered too, but the three above are what most people are asking about when they ask about security, so this page focuses there.

2. Encryption

Data is encrypted in transit and at rest. Traffic to and from the platform runs over TLS. Stored data, including knowledge base content and conversation history, is encrypted on disk.

That applies to everything you put into the platform, not a subset of it.

3. API keys and BYOK

If you bring your own provider key, it's encrypted and scoped to the workspace where you added it. It isn't shared across workspaces or accounts.

We don't log key values. We don't send a key anywhere except the provider it belongs to, for requests originating from your workspace.

4. Infrastructure

Our storage and databases run on infrastructure from SOC 2 certified cloud providers, hosted in the United States and the European Union.

To be clear about what that means: the certification belongs to our cloud providers, not to Nivon. We're telling you what we run on, not claiming an audit we haven't done.

5. Access control

Access to production systems is restricted to the people who need it to operate and support the platform, and that access is logged.

We don't browse customer knowledge bases or conversation history for curiosity or product research. Access happens for operations, security, or a support request you've raised.

6. How AI processing is secured

Official API access only. We reach every model through the provider's official commercial API. No resellers, no unofficial endpoints, no scraped access, no workarounds. This matters because official API access comes with contractual data terms. Backdoor access doesn't.

You choose where requests go. When you configure a Agent, you pick the model that powers it. When that Bot receives a message, it goes to the provider you selected. That routing is the product working as designed, and we tell you plainly that it happens.

No training on your data. We don't use your knowledge base, Agent configurations, or end-user conversations to train models of our own. We also vet providers before adding a model to the platform, and choose ones whose API terms exclude using customer input to train their models.

One thing to keep in mind. Once a message leaves Nivon for a model provider, it's handled under that provider's terms, which we vet but don't control. Avoid uploading sensitive personal data or confidential information to a Agent’s knowledge base unless your use case genuinely needs it.

7. Payments

Payments are processed by Stripe under its own security and privacy practices. Card data is encrypted in transit. We never see or store your full card details.

8. Who your data reaches

We share data only where it's reasonably necessary to run the Service:

AI model providers you select. Your Agent's messages go to the provider whose model you chose.

Service providers. Companies that help us operate Nivon, all under confidentiality obligations.

Legal and safety. Where required by law, or to protect Nivon, our users, or the public.

Where data moves across borders, we apply appropriate safeguards.

9. Retention and deletion

We keep your knowledge base and conversation history so your Agents keep working and features like history and continuity function correctly. It stays until you delete it or close your account.

Deletion is yours to trigger. You can remove individual Agents, knowledge base content, and conversation history, or close the account entirely.

10. Your side of it

Security is shared. A few things sit with you:

  • Keep your credentials confidential and don't share Account access.
  • Review what your Agents say before putting them in front of customers. AI responses are probabilistic and can be wrong.
  • Be deliberate about what goes into a knowledge base. If it doesn't need to be there, leave it out.
  • If you think your Account has been compromised, email [support@nivon.ai] immediately.

11. Abuse monitoring

We use automated systems and human review to enforce our acceptable use rules, and we may suspend access to protect the platform, our users, or third parties. This exists to catch abuse of the Service, not to inspect your business content.

12. Compliance and your rights

We handle personal data in line with applicable data protection laws, including the GDPR where it applies to you.

We're the data controller for your account and billing data, and a processor for the knowledge base content and end-user conversations your Agents handle on your behalf. If you're running support for your own customers, you're the controller of their data and we process it under your instructions.

A Data Processing Addendum covering that relationship is available on request. Email [privacy@nivon.ai].

You can access, correct, delete, export, or restrict processing of your data, and withdraw consent you previously gave. Details are in our Privacy Policy.

13. Reporting a problem

Found a vulnerability, or think something's wrong? Email [security@nivon.ai] with enough detail for us to reproduce it. We'll acknowledge the report and keep you updated on what we find.

Please don't test against other customers' data or run anything that degrades the service for other users.

If we discover a security incident affecting your data, we'll notify you without undue delay, along with what we know and what we're doing about it.

14. The honest caveat

No system can be guaranteed fully secure. We use reasonable technical and organizational measures, we tell you what they are, and we don't oversell them. Nobody can promise perfection, and you should be skeptical of anyone who does.