generated: '2026-08-01' method: searched probe: true source: https://www.conviva.ai/security/ url: https://www.conviva.ai/security/ name: Conviva Trust Center description: >- Conviva publishes a Trust Center page covering compliance certification, data protection, encryption, access management, monitoring and vulnerability management. It is a narrative trust page, not a document-portal trust center (no SafeBase/Vanta/Drata portal, no downloadable audit reports behind an NDA request flow). # Only ISO/IEC 27001:2022 is claimed as Conviva's OWN certification. SOC 1 / SOC 2 are # explicitly attributed to the third-party cloud platforms Conviva hosts on, NOT to Conviva. certifications: - name: ISO/IEC 27001:2022 scope: Conviva (own certification) evidence: >- "Conviva is certified under ISO/IEC 27001:2022, the globally recognized standard for information security management systems (ISMS)." regulatory_compliance: - name: GDPR evidence: "Conviva's services are compliant with the EU General Data Protection Regulation (GDPR)" - name: UK GDPR evidence: "Conviva's services are compliant with ... UK GDPR" - name: CCPA evidence: "Conviva's services are compliant with ... the California Consumer Privacy Act (CCPA)" inherited_certifications: - name: SOC 1 scope: third-party cloud hosting platforms (not Conviva) - name: SOC 2 scope: third-party cloud hosting platforms (not Conviva) - name: ISO 27001 scope: third-party cloud hosting platforms (not Conviva) inherited_note: >- "Conviva hosts its cloud infrastructure on trusted third-party platforms that comply with industry-recognized standards such as SOC 1, SOC 2, and ISO 27001, among others." This is an inherited-control statement about hosting providers, not a Conviva audit report. practices: encryption: In-transit and at-rest encryption of customer data. access_management: Multi-factor authentication and role-based access control. monitoring: Continuous monitoring for security threats, performance issues and service disruption. vulnerability_management: third_party_testing: Annual third-party penetration testing. scanning: Continuous scanning of applications and infrastructure for vulnerabilities. data_transfers: Standard Contractual Clauses (SCCs) for personal data transfers outside the EEA and UK. contacts: privacy: privacy@conviva.ai support: support@conviva.com security_disclosure: null # no dedicated security@ address or coordinated-disclosure channel published related: privacy_policy: https://legal.conviva.ai/privacy-policy/ terms_of_use: https://legal.conviva.ai/terms-of-use/ gdpr: https://legal.conviva.ai/gdpr/ cookie_policy: https://legal.conviva.ai/cookie-policy/ ccpa: https://legal.conviva.ai/ccpa-page/ subprocessors: https://legal.conviva.ai/conviva-subprocessors/ privacy_request_portal: https://privacyportal.onetrust.com/webform/68049a8d-acc0-4473-b871-a599fe9c9650/2a3e0a9e-438d-4a49-8a69-ca9d5d423428 status_page: https://status.conviva.com/ gaps: - No /.well-known/security.txt on conviva.com, conviva.ai, docs.conviva.ai or api.conviva.com (all 404). - No published coordinated vulnerability disclosure policy, bug bounty, or security@ reporting address. - SOC 2 is inherited from hosting providers only; Conviva publishes no SOC 2 report of its own. x-evidence: fetched: '2026-08-01' url: https://www.conviva.ai/security/ http_status: 200 emails_decoded_from: Cloudflare data-cfemail obfuscation on the page