Convexly Trust Center

One place to evaluate how Convexly handles security and data.

This page is the front door for a security or procurement review. It links to our security posture, subprocessors, platform status, independence policy, and the audit-chain verifier, and it sets out the controls we provide and the data rights you keep.

Posture stated 2026-06-28. Questions: security@convexly.app.

Security posture

The controls below are in place today. Each is described against the live service.

ControlStatusDetail
Encryption in transitProvidedTLS protects all connections to the web application and API.
Encryption at restProvidedData is encrypted at rest on the managed PostgreSQL database with AES-256.
Access controlProvidedPostgreSQL row-level security plus JWT authentication govern access to customer data, with server-side enforcement on paid endpoints. Administrative keys are not exposed to the browser.
Data residencyUnited StatesCustomer data is stored and processed in United States regions. Edge request handling is global; persistent data is US.
Subprocessor transparencyPublishedA current, maintained subprocessor list with per-provider DPA links and a change-notice policy for parties under a signed DPA.
Vulnerability disclosuresecurity@convexly.appGood-faith reports are acknowledged as quickly as practical. Reporters are asked to avoid accessing other users' data, degrading the service, or disclosing before a reasonable investigation window.
Data Processing AddendumAvailableA standard DPA is available for execution under an enterprise engagement.

SOC 2, a third-party penetration-test summary, a measured availability SLA with service credits, and SSO (SAML / OIDC), SCIM, and organization-level MFA enforcement are addressed under an enterprise engagement. Reach out to security@convexly.app to scope these for your review.

Data rights and export on termination

  • You own your account data. The data you submit, your watchlists, your imports, and your saved work remain yours.
  • Data export is available in CSV and JSON formats so your records are portable and not locked in.
  • On termination, your account data is deleted on request, and inactive accounts can be removed under the retention practices in the privacy policy. We do not keep your data indefinitely against your wishes.
  • Customer data is not used to train any model. AI features process only the specific text you choose to submit at the moment you use them.
  • Public on-chain wallet addresses submitted to the free analyzer are not persisted beyond the analysis round-trip; the analysis queries public on-chain data only.

These statements are consistent with the independence policy and the privacy policy. Where a practice is policy rather than a contractual term, it becomes contractual when written into a signed agreement.

Security questionnaire (pre-filled)

A short, plain answer set to the questions a vendor review asks first. It is meant to shorten the back-and-forth, not to replace a full questionnaire your team may send.

Is data encrypted in transit and at rest?+

Yes. TLS protects all connections in transit. Data at rest is encrypted with AES-256 on the managed PostgreSQL database.

How is access to customer data controlled?+

Access to customer data is enforced with PostgreSQL row-level security and JWT authentication, with paid features enforced server-side. Administrative keys are restricted to backend operations and are not exposed to the browser.

Where is data stored and processed (residency)?+

Customer data is stored and processed in United States regions. Edge request handling is global; persistent storage is US.

What is your incident and vulnerability-disclosure posture?+

Vulnerabilities can be reported to security@convexly.app with reproduction steps, the affected URL or API path, and impact. Good-faith reports are acknowledged as quickly as practical. Incident-response procedures and breach-notification commitments are defined under an enterprise contract.

Who are your subprocessors and how are changes communicated?+

The current subprocessor list is published at /legal/subprocessors with each provider purpose, the data shared, the region, and a link to that provider DPA. Parties under a signed DPA receive advance notice of material changes per that agreement.

Do you offer a Data Processing Addendum?+

Yes. A standard DPA is available for execution under an enterprise engagement.

What are my data rights, including export and deletion?+

You own your account data. Export is available in CSV and JSON. On termination, account data is deleted on request. Customer data is not used to train any model. The full statement is in the Data rights section above.

Do you support SSO, SCIM, or organization-level MFA enforcement?+

SAML/OIDC single sign-on, SCIM provisioning, and organization-level MFA enforcement are addressed under an enterprise engagement. Reach out to security@convexly.app to scope your identity requirements.

What about SOC 2, penetration testing, and availability commitments?+

SOC 2, a third-party penetration-test summary, and a measured availability SLA with service credits are addressed under an enterprise engagement. Contact security@convexly.app to begin that process for your review.

Need the diligence package?

The enterprise data room indexes the architecture and security overview, subprocessor list, methodology and evidence, and the independence statement, with availability labels attached. Access to gated artifacts is requested through the enterprise process.