Effective date: 28 May 2026. The technical and organizational measures Truvyo applies to protect Customer data. Replaces the standard security questionnaire for most procurement reviews.
| Compute | Cloudflare Workers — V8 isolates, no persistent server processes |
| Storage | Cloudflare D1 (SQLite-backed), Vectorize, R2; Customer region-selected |
| State | Durable Objects per conversation (SQLite-backed, single-region) |
| LLM | Anthropic API (Claude Haiku 4.5 + Sonnet 4.6) |
| Edge cache | Cloudflare KV for tenant-key lookup (60 s TTL) |
/v1/admin/*, /v1/pipeline/*) are gated by a deployment-wide internal secret stored in Cloudflare's secret store, not in source code.| Plan | Availability target | SLA credits |
|---|---|---|
| Starter | 99.5% | None (terminate without penalty if below) |
| Growth | 99.9% | None (terminate without penalty if below) |
| Scale | 99.9% | Pro-rated credits on SLA addendum |
| Enterprise | 99.95% | Full SLA in signed MSA |
status.truvyo.ai.If you find a security vulnerability, please report it to security@truvyo.ai. We acknowledge within 24 hours, share a remediation timeline within 5 business days, and credit researchers in our post-incident summary unless asked to keep the report private.
We don't currently run a paid bounty program. Significant findings receive a thank-you and, where appropriate, swag and credit.
Customer is permitted to conduct penetration testing of the Service against the Customer's own tenant, provided that: testing is coordinated with us at security@truvyo.ai at least 7 days in advance; testing does not target other tenants; and the Customer shares findings with us at the conclusion of the test.