How we protect your data and keep the service reliable.
Last updated: April 21, 2026
TL;DR: Your data is stored in India (Azure Central India), encrypted at rest (AES-256) and in transit (TLS 1.2+), never used to train AI models, and never sold. We target 99.9% uptime and have a clear SOC2 roadmap for 2026.
All Konverze AI data — including your chatbot training data, conversation logs, account information, and uploaded documents — is stored on Microsoft Azure infrastructure located in the Central India region (Pune).
This means your data stays in India. We do not store primary data in the US, EU, or any other region. For EU customers, conversations are processed via AI APIs (OpenAI) with appropriate Standard Contractual Clauses (SCCs) in place — see Section 5 below.
All data transmitted between your browser, the Konverze AI widget, and our servers is encrypted using TLS 1.2 or higher. We enforce HTTPS-only connections. HTTP connections are automatically redirected to HTTPS at the Cloudflare and Nginx layers before reaching our application.
All data stored on Azure infrastructure is encrypted at rest using AES-256 encryption — the same standard used by banks and government agencies. Encryption keys are managed by Azure Key Vault with automated rotation.
We use httpOnly, Secure, SameSite=Lax cookies for authentication. This means your session token is completely inaccessible to JavaScript — it cannot be stolen by XSS attacks. We do not store tokens in localStorage or sessionStorage.
We target 99.9% uptime for the Konverze AI platform. This translates to less than 8.7 hours of unplanned downtime per year.
For real-time status, visit status.konverze.in.
When your chatbot processes a visitor message, the message is sent to our AI provider (OpenAI) to generate a response. This is the only third-party sub-processor that receives conversation data.
Per OpenAI's API terms: data sent via the API is not used to train OpenAI models. Messages are processed ephemerally to generate a response and are not stored beyond 30 days for abuse monitoring purposes.
SOC2 Type II — Roadmap: We are on a SOC2 Type II compliance roadmap targeting certification in Q4 2026. Enterprise customers who require SOC2 before this date can request our current security documentation package at [email protected].
We take security vulnerabilities seriously. If you discover a security issue in the Konverze AI platform, please report it responsibly:
Email: [email protected] with subject line "Security Disclosure"
Response time: We will acknowledge your report within 24 hours and provide a resolution timeline within 72 hours.
Scope: All subdomains of konverze.in and konverze-related infrastructure
We request: Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to fix it (coordinated disclosure).
We do not currently offer a bug bounty programme but we do thank researchers publicly for responsible disclosures.
For enterprise customers and organisations subject to GDPR who require a formal Data Processing Agreement (DPA), we provide one on request. The DPA covers:
To request a DPA, email [email protected] with subject line "DPA Request".
Security enquiries: [email protected]
DPA requests: Subject line "DPA Request"
Responsible disclosure: Subject line "Security Disclosure"
SOC2 documentation: Subject line "Security Documentation"
© 2026 Konverze AI. All rights reserved. · Terms · Privacy · Plan Policy · FAQ