TalkVend

TRUST AND SECURITY

Enterprise security, proven by audit.

Every conversation, attachment and automated decision runs inside a controlled, encrypted and auditable environment, independently reviewed by Deloitte.

hello@talkvend.com

Certifications and frameworks

SOC 2 Type II

Audited

Security, availability and confidentiality controls audited over an observation period, with report available under NDA.

ISO/IEC 27001

Certified

Information security management system with documented scope, risk treatment plan and recurring internal audits.

LGPD

Compliant

Brazilian data protection program: legal basis mapping, data subject rights workflow and records of processing.

GDPR

Compliant

European framework with data processing agreements, transfer safeguards and documented subprocessor governance.

Reports, certificates and the full control matrix are shared with prospects and customers under NDA.

How the platform protects the operation

Encryption everywhere

TLS 1.2+ in transit and AES-256 at rest for conversations, attachments, logs and backups. Keys are managed and rotated by a dedicated key management service.

Access is a boundary, not a setting

Roles, configurable admin scope and segment scope. The inbox is the real boundary: an agent only reaches conversations inside the inboxes assigned to them.

Auditable by design

Every event inside a conversation carries author and timestamp: assignment, transfer, note, template, workflow publication and export.

Change control on automation

Nothing reaches production without approval. Workflows have draft, test and versioned publication, so any change can be reviewed and rolled back.

AI under human control

The AI never sends anything the company has not approved in the flow, works only over the operation's own content, and a person can take the conversation at any moment.

Tenant isolation

Each account only sees its own data, enforced at the data layer with row level policies rather than at the interface.

Infrastructure

  • Hardened cloud infrastructure with segregated production environment
  • Continuous backups with restore testing
  • High availability architecture and monitored capacity
  • Secrets vault for every integration credential

People and process

  • Background screening and confidentiality agreements
  • Mandatory annual security and privacy training
  • Least privilege access with periodic review
  • Peer reviewed code and protected release pipeline

Testing and assurance

  • Independent penetration testing
  • Automated dependency and vulnerability scanning
  • Independent audit conducted by Deloitte
  • Vendor and subprocessor risk assessment

Incident response

A documented plan with named owners, severity classification, containment steps and customer notification. Post incident reviews are written and shared with affected accounts.

Responsible disclosure

Found a vulnerability? Write to hello@talkvend.com with the steps to reproduce. We acknowledge every valid report and never pursue researchers acting in good faith.

Send us your security questionnaire.

Our team answers vendor assessments, DPIA requests and architecture reviews with your security and legal teams.