Six documents, every third party named, and a section on what Amvio has not done that is longer than most companies would print. All of it written to be read by somebody deciding whether to take a risk, not by somebody who has already decided.
Paste this page into the first box of a questionnaire. Everything the rest of the boxes ask for is one click from here.
Architecture, tenant isolation, authentication, what is encrypted and where — and one numbered section listing what has not been done.
read it →your counselWhat is collected, what is refused, how long it is kept, and the rights a person has over it. Amvio does not train models on customer data and does not sell personal information.
read it →your reviewerEvery third party in the path, named, with what each one actually receives — read off the code rather than off a vendor list.
read it →your procurement teamWritten and published, rather than produced on request after two weeks and a chase. Read it before you ask for it.
read it →your customersThe same facts, written for the person actually talking to Amvio inside your product rather than for the company buying it.
read it →your counselThe agreement itself, and the acceptable-use line that sits under it.
read it →This list is honest rather than flattering, and it is the list to base a risk decision on. It is section 8 of the security policy, moved to the top of this page on purpose.
None is in progress. If your procurement process requires a certification today, Amvio will not pass it.
No independent security audit has been carried out.
Reports are welcome and handled directly, but there is no managed programme and no reward.
No data residency choice and no single-tenant deployment option.
For dashboard accounts. Your end users are not asked to make an Amvio account at all.
Deleting a specific conversation or purging a workspace is handled by request rather than by a button.
Amvio is an early-stage product and this is what that costs you. The full section, with the architecture it sits beside, is on the security page.
Answered here so a reviewer can move on, and cited so they can check. Every answer names the clause it comes from.
No. Amvio does not use one customer’s data to answer anyone else’s questions, does not train models on customer data, and does not sell personal information or share it for cross-context behavioural advertising.
Privacy, §1.3 →Conversations, memory and derived signals persist for as long as the workspace exists — durable memory is what the product is for, so this is the feature rather than incidental retention. On termination, data is deleted within 30 days of a written request and within 90 days in any event.
Privacy, §7.1 and §7.3 →9 named third parties — 4 infrastructure, 4 model providers and 1 that reads the documentation you point it at — plus 2 more that receive nothing unless you connect them. Each is listed with what it actually receives.
Sub-processors →Only to Google, which runs the live voice session. Microphone audio and — where screen sharing is on — still frames of the shared screen. It is the only provider that receives either, and the sub-processor page says so in those words.
Sub-processors →It is already written and published rather than produced on request. Read it first and tell us what your counsel needs changed.
DPA →Yes, by request — a specific conversation or an entire workspace. There is no self-serve control for it in the dashboard today, and the security page lists that as a gap rather than a policy.
Privacy, §7.4 →Not “industry-standard providers”. The list below is the same array the sub-processor page renders, so the two cannot drift apart.
Everything Amvio stores: accounts, conversations, uploaded files, indexed documentation, and what Amvio has learned.
All traffic to the service in transit, including live session data as it passes through.
Dashboard requests and their authentication cookies. Separately, a cookieless count of page views: the page, the referring site, and coarse device and country information.
The address of a page that failed and an error reference, with the browser and operating system. Not the contents of the page, and no session recording.
Microphone audio and, where screen sharing is enabled, still frames of the shared screen, along with the text of the conversation. This is the only provider that receives audio or images.
Conversation text and excerpts of your documentation. Every piece of knowledge you give Amvio is embedded through OpenAI, whichever model answers your customers.
Conversation text and excerpts of your documentation, where a Claude model is selected.
Conversation text and excerpts of your documentation, where Grok is selected.
The URLs you ask it to index, and it returns their contents. It receives no conversation data.
Nothing unless you connect it. Once connected, Amvio reads the pages you authorise.
Nothing unless you connect it.
Every row was read off the code rather than off a vendor page. If a provider is added to the backend it is added here in the same change, because a sub-processor list that lags the product is worse than none — it is the one somebody relied on.
Three things, and none of them needs a call with us first.
It links every document, names every sub-processor, and states the gaps. A reviewer who reads only this page has enough to form a view.
It is published, so your counsel can mark it up on their own schedule rather than waiting on ours. Tell us what needs to change and we will talk about it.
If a question on your form has no answer on this site, that is worth knowing — it usually means the document is missing rather than the answer is. Email hello@amvio.ai.
Tell us and it goes into the document rather than into a reply. Every gap somebody has had to email about is a gap the next reviewer would have hit too — including the vulnerability you would rather report than exploit.
Your users are already having the conversation. Right now it is with nobody.