amvioThe conversationThe voice lineHandoverWhat it was givenDiscoveryKnowledgeWhat it keepsAccount memoryCognitionYour teamThe dashboardStudioHeld by the accountCustomer successOnboarding specialistReached by the questionCustomer supportProduct specialistRevenueSales engineerRenewalsProduct intelligenceUser researchDocumentationHow it worksThe argumentWhy Amviovs. more headcountWhat it is notvs. a support chatbotvs. your help centrevs. in-app toursThe documentsSecurityPrivacyTermsFor your reviewerTrust centreSub-processorsDPAFor your usersFor end userssign inbook a demo

Everything your security reviewer will ask for, at one address.

Six documents, every third party named, and a section on what Amvio has not done that is longer than most companies would print. All of it written to be read by somebody deciding whether to take a risk, not by somebody who has already decided.

SecurityThe DPA

The six documents, and who opens each one.

Paste this page into the first box of a questionnaire. Everything the rest of the boxes ask for is one click from here.

your security engineer

Security

Architecture, tenant isolation, authentication, what is encrypted and where — and one numbered section listing what has not been done.

read it →
your counsel

Privacy

What is collected, what is refused, how long it is kept, and the rights a person has over it. Amvio does not train models on customer data and does not sell personal information.

read it →
your reviewer

Sub-processors

Every third party in the path, named, with what each one actually receives — read off the code rather than off a vendor list.

read it →
your procurement team

DPA

Written and published, rather than produced on request after two weeks and a chase. Read it before you ask for it.

read it →
your customers

For end users

The same facts, written for the person actually talking to Amvio inside your product rather than for the company buying it.

read it →
your counsel

Terms

The agreement itself, and the acceptable-use line that sits under it.

read it →

What Amvio has not done, before you have to ask.

This list is honest rather than flattering, and it is the list to base a risk decision on. It is section 8 of the security policy, moved to the top of this page on purpose.

No SOC 2 or ISO 27001

None is in progress. If your procurement process requires a certification today, Amvio will not pass it.

No third-party penetration test

No independent security audit has been carried out.

No bug bounty programme

Reports are welcome and handled directly, but there is no managed programme and no reward.

No customer-managed keys

No data residency choice and no single-tenant deployment option.

No SSO, SCIM or enforced MFA

For dashboard accounts. Your end users are not asked to make an Amvio account at all.

No self-serve audit export or deletion

Deleting a specific conversation or purging a workspace is handled by request rather than by a button.

Amvio is an early-stage product and this is what that costs you. The full section, with the architecture it sits beside, is on the security page.

The six questions that always come first.

Answered here so a reviewer can move on, and cited so they can check. Every answer names the clause it comes from.

Do you train models on our data?

No. Amvio does not use one customer’s data to answer anyone else’s questions, does not train models on customer data, and does not sell personal information or share it for cross-context behavioural advertising.

Privacy, §1.3

How long do you keep it?

Conversations, memory and derived signals persist for as long as the workspace exists — durable memory is what the product is for, so this is the feature rather than incidental retention. On termination, data is deleted within 30 days of a written request and within 90 days in any event.

Privacy, §7.1 and §7.3

Who else sees it?

9 named third parties — 4 infrastructure, 4 model providers and 1 that reads the documentation you point it at — plus 2 more that receive nothing unless you connect them. Each is listed with what it actually receives.

Sub-processors

Does anything leave as audio or images?

Only to Google, which runs the live voice session. Microphone audio and — where screen sharing is on — still frames of the shared screen. It is the only provider that receives either, and the sub-processor page says so in those words.

Sub-processors

Can we get a DPA signed?

It is already written and published rather than produced on request. Read it first and tell us what your counsel needs changed.

DPA

Can a customer be deleted?

Yes, by request — a specific conversation or an entire workspace. There is no self-serve control for it in the dashboard today, and the security page lists that as a gap rather than a policy.

Privacy, §7.4

Every third party in the path, named.

Not “industry-standard providers”. The list below is the same array the sub-processor page renders, so the two cannot drift apart.

11 named4 categoriesone that receives audio
InfrastructureWhere it runs and where it is stored.
Supabase
Database, authentication and file storage

Everything Amvio stores: accounts, conversations, uploaded files, indexed documentation, and what Amvio has learned.

Railway
Hosting for the Amvio API

All traffic to the service in transit, including live session data as it passes through.

Vercel
Hosting and page-view analytics for this dashboard

Dashboard requests and their authentication cookies. Separately, a cookieless count of page views: the page, the referring site, and coarse device and country information.

Sentry
Error tracking

The address of a page that failed and an error reference, with the browser and operating system. Not the contents of the page, and no session recording.

Model providersWho the words are sent to, and in one case the audio.
Google
The live voice session (Gemini Live)

Microphone audio and, where screen sharing is enabled, still frames of the shared screen, along with the text of the conversation. This is the only provider that receives audio or images.

OpenAI
Text generation, and all knowledge embeddings

Conversation text and excerpts of your documentation. Every piece of knowledge you give Amvio is embedded through OpenAI, whichever model answers your customers.

Anthropic
Text generation and structured extraction (Claude)

Conversation text and excerpts of your documentation, where a Claude model is selected.

xAI
Text generation (Grok)

Conversation text and excerpts of your documentation, where Grok is selected.

ContentReading the documentation you point Amvio at.
Firecrawl
Reading documentation sites you point Amvio at

The URLs you ask it to index, and it returns their contents. It receives no conversation data.

Only if you connect themNothing reaches these unless you switch them on.
Notion
Optional knowledge source

Nothing unless you connect it. Once connected, Amvio reads the pages you authorise.

Linear
Optional integration

Nothing unless you connect it.

Every row was read off the code rather than off a vendor page. If a provider is added to the backend it is added here in the same change, because a sub-processor list that lags the product is worse than none — it is the one somebody relied on.

What to do when the questionnaire arrives.

Three things, and none of them needs a call with us first.

01

Send them this page

It links every document, names every sub-processor, and states the gaps. A reviewer who reads only this page has enough to form a view.

02

Read the DPA before asking for it

It is published, so your counsel can mark it up on their own schedule rather than waiting on ours. Tell us what needs to change and we will talk about it.

03

Ask us the thing that is not written down

If a question on your form has no answer on this site, that is worth knowing — it usually means the document is missing rather than the answer is. Email hello@amvio.ai.

Book a demoRead the security page

Found something this page does not answer?

Tell us and it goes into the document rather than into a reply. Every gap somebody has had to email about is a gap the next reviewer would have hit too — including the vulnerability you would rather report than exploit.

Your users are about to have someone.

book a demoget started
it starts working with them the day you install itone line of code · no sdk · no integrations

Your users are already having the conversation. Right now it is with nobody.

book a demoget started
amvio
© 2026 Amvio, Inc.termsprivacyacceptable use