Partner programs handle sensitive revenue data. Here's exactly how we protect yours.
All data is encrypted via TLS 1.2+ between your browser, our servers, and our database. No plaintext communication.
Data stored in Convex (AWS us-east-1) is encrypted at rest using AES-256. Backups are also encrypted.
Every deal approval, commission calculation, and payout is logged with a timestamp and actor. Tamper-evident trail for every action.
Powered by Clerk — industry-standard auth with bcrypt password hashing, optional MFA, and secure session management.
Convex provides continuous, automatic backups with point-in-time recovery. We test restores periodically.
Security incidents are logged, investigated, and disclosed within 72 hours per GDPR requirements. Email security@covant.ai to report.
Covant runs on:
We use Vercel's production environment with separate production and development deployments. No development data touches production infrastructure.
Covant enforces data isolation at the application layer:
Internal access to production data is limited to engineers who require it for support or debugging. All internal access is logged.
A Data Processing Agreement (DPA) for GDPR compliance is available at covant.ai/dpa. For enterprise security reviews, email security@covant.ai.
If you discover a security vulnerability in Covant, please email security@covant.ai. We ask that you:
We will acknowledge all reports within 48 hours and keep you updated on our progress.
Security questions or enterprise security review requests: security@covant.ai
Privacy questions: privacy@covant.ai