Trust center
What the service holds, where it lives, who else touches it, and what we will not claim. Written for the person whose job is to ask.
Last updated 29 September 2026
What the service holds
A business running on Aqvitus stores its customers’ conversations across chat, email, SMS, voice and RCS — messages, call recordings and transcripts where it records them, attachments — together with contact records, custom attributes, consents, the knowledge its AI answers from, the rules and procedures it wrote, and an append-only event log of everything that happened.
That is customer contact data and, depending on the business, order and payment references, support history and whatever a customer chose to type. It is the business’s data. The business decides what is collected and why; EvolvLabs processes it on that business’s behalf. For the accounts of the people who sign in, and for visitors to this website, EvolvLabs is the controller. The Privacy policy sets out the split.
Where it runs
The application, its database and its backups run on Google Cloud in the United States. Traffic reaches it through Cloudflare, over a tunnel — the application is not exposed to the public internet directly. Backups are encrypted and held in Google Cloud Storage.
Aqvitus can also be run somewhere else entirely. The self-hosted profile runs in your own environment with local open-weight models doing the classifying, extracting and embedding, and nothing leaving the box except to addresses you allowed — and that the egress outside that list is zero is verifiable, not promised. The Security page describes the three shapes.
Who else touches it
Every outside service the production service uses today, what it does, and what it receives. There are no others. If we add one, this table changes before it goes live.
| Service | What it does | What it receives |
|---|---|---|
| Google Cloud | Runs the application and its database, and holds the encrypted backups in Google Cloud Storage. | Everything the service stores, as stored — encrypted personal fields included. |
| Cloudflare | DNS, the network edge and the secure tunnel in front of the app. Also hosts this website. | Request traffic in transit: IP address, browser, the page or endpoint asked for. |
| OpenAI | The AI model API that writes replies, sorts conversations and builds the search index. | Conversation and knowledge text with personal details already replaced by tokens. |
| Resend | Sends notification and invitation email, and receives mail forwarded to a workspace address. | The messages themselves, and the addresses they are going to or came from. |
| Google Workspace | Sends the email that leaves from support@aqvitus.com. | The messages sent from that address. |
| Google sign-in | Optional: signing in to a workspace with a Google account instead of a password. | Only the sign-in itself. Nothing about your customers or your conversations. |
| Geoapify | Draws the map image of a visitor’s approximate city on the live board. | A city-level coordinate. No address, no precise location, no identity. |
Personal details are replaced with tokens before any text is sent to a model, and put back only on our own servers afterwards. The model provider does not receive your customers’ names, addresses or card and order references.
What you choose, not us
- Your own AI model key. A workspace can bring its own model provider account. That provider then processes the text under your agreement with it, not ours, and your model spend passes through at cost.
- Your own carrier. SMS, voice and RCS run on your carrier account, with your numbers and your registration. We do not resell a carrier and we do not put one between you and your customers.
In both cases the supplier is yours, and neither appears in the table above because neither is our choice to make.
How the product protects it
The short version. Security has the whole chain, with the refusals shown working.
- Each workspace is isolated hard — its data, its secrets, its search indexes, its rate limits and its model settings — with row-level enforcement in the database underneath the application’s own checks.
- Personal fields are encrypted with keys belonging to one workspace, and erasing a customer destroys the keys rather than hoping a delete reached every copy.
- Personal details never appear in a log, in event metadata, or in a prompt. They are tokenised before a model call and put back server-side.
- The model proposes; the platform disposes. Every action the AI wants to take is validated against a schema and then against the deterministic rules your workspace wrote. What the rules do not allow does not happen, no matter what the AI was told.
- A second factor for anyone who can approve. Owner, admin, manager and lead must enrol one — the credential bar follows the authority.
- An append-only, hash-chained audit ledger. Every action lands in it with the tool and version, redacted parameters, the actor chain, the policy decision and how an approval resolved. Records are chained day by day per workspace, and exports carry the hashes so tampering shows.
- Secrets live in a vault, never in a prompt, an event or a log, and a deployment refuses to start on a development key.
- A per-workspace outbound allowlist for model providers and connected tools, whichever shape you run.
What we do not claim
Aqvitus holds no security certification. Not SOC 2, not ISO 27001, not HIPAA, not PCI DSS, and there is no GDPR badge on this page. We are not going to put a seal here that an auditor did not give us. When one is earned, this page and the Security page will name it, the date and its scope.
What the platform has instead is the evidence those controls ask for, built in rather than assembled afterwards: an append-only event log, a hash-chained audit ledger with exports, per-workspace keys, erasure that destroys the key, and roles enforced on the server. Send us a questionnaire and we will answer it, field by field, and say plainly where the answer is “not yet”.
We are not a HIPAA business associate and we do not sign BAAs today. Do not put protected health information into a workspace, and do not put full payment card numbers anywhere — Aqvitus is not a card environment.
Who is responsible for what
- EvolvLabs owns the security of the application and its architecture, isolation between workspaces, enforcement of roles and approvals, the integrity of the audit ledger, keeping personal data out of prompts and logs, the security of the hosting and of our own systems, and responding to vulnerability reports.
- Your business owns the rules and lanes you set and therefore what the AI is allowed to send on its own, who holds which role and removing people who leave, the consents behind the messages you send and the calls you record, your carrier and model-provider accounts if you bring them, the retention periods you choose, the devices and networks your team uses, and the legal obligations that come with your industry.
This website
aqvitus.com is a static site served by Cloudflare over TLS. It sets no cookies of its own, runs no analytics, carries no advertising and tracks nobody. It holds no customer data and accepts none — there is no form on it. It loads one typeface from Google Fonts, which means Google sees the requesting IP address.
Reporting a problem
Security vulnerabilities: support@aqvitus.com, under the security disclosure policy, which sets out the ground rules and the safe harbour we extend to good-faith research. The same policy is published at /.well-known/security.txt.
Security reviews, questionnaires, a data processing agreement, or a question this page did not answer: the same address, or the contact page.
Related: Security · Privacy · Terms · Acceptable use