Trust

Your data stays in your building.

Convoy Automation is a build firm, not a SaaS platform, and the difference decides most of what follows. A CIS is deployed into infrastructure you own and control. We do not run a multi-tenant product that your data sits inside, and we do not warehouse your records on our own servers. What we hold is access, for as long as you grant it.

What we hold, what we inherit

We will not imply a certification we do not have.

Convoy Automation does not hold SOC 2, ISO 27001 or HIPAA certification, and we will not imply otherwise. We are a small build firm. What we can tell you honestly is where the audited controls actually sit: in the platforms a CIS runs on, most of which are accounts you already own.

Inherited · audited controls held by the platforms a CIS runs on

Inherited

Your cloud account

A CIS is deployed into your infrastructure, so the certifications that apply are the ones your provider already holds under your account, not ours.

Inherited

Major cloud providers

AWS, Azure and Google Cloud each maintain SOC 1/2/3 and ISO 27001 programmes at the infrastructure layer. Which applies depends on where your CIS is deployed.

Inherited

Anthropic (Claude)

The reasoning engine inside a CIS is Anthropic's Claude. Anthropic publishes its own security and privacy commitments, including commercial terms that exclude customer data from training. The provider for your engagement is named in Schedule A.

Inherited

Your existing systems

QuickBooks, Microsoft 365, Salesforce and the rest carry their own compliance posture. A CIS reads them through their published APIs; it does not change how they are governed.

Available on request

On request

Sub-processor list

The exact providers for your engagement, in writing.

On request

Data Processing Agreement

Ask and we will send one.

On request

Security questionnaire

Send yours and we will complete it directly rather than pointing you at a page.

On request

Schedule A data map

The signed scope document names every system, field and access level. It is the real answer to most security questions.

Email [email protected] and we will send any of these directly.

01 / Data Security

Data Security

Where your data lives

In your environment. A CIS is deployed to infrastructure you own, under accounts you control. We are not a destination your records are copied to.

Credentials and tokens

Held in your secret store, scoped to the narrowest permission the job needs, and read-only wherever reading is enough. Every credential is one you issue and can revoke without asking us.

Encryption

In transit over TLS, and at rest using the encryption your platform provides. We do not build our own cryptography.

Access control

Role-based access inside the dashboard, with an audit record of who did what and which agent acted. Named human accounts, never a shared login.

Monitoring

Watchdog is the standing unit for this: failure detection, upkeep as platforms change, and owner-set automatic lockdown when activity crosses a threshold you set.

Incident response

If something goes wrong we tell you, in writing, with what happened, what was affected and what we are doing. We would rather be early and wrong about severity than late.

02 / Data Governance

Data Governance

Data flow

Mapped during the recon and written into the signed Schedule A before any build work starts. You approve the map. Nothing moves that is not on it.

Who can access

Only the people working on your build, only for as long as the engagement needs it, and only through accounts you created. There is no standing Convoy access to a client system after handover unless you keep a maintenance plan running.

Retention

We do not retain copies of your operational data. Working artefacts created during the build - schemas, configuration, documentation - stay with the system, which is yours.

Offboarding

You revoke the accounts. Because the system runs in your environment and the code is yours, there is nothing for us to hand back and nothing for us to keep.

Sub-processors

The providers a CIS runs on are chosen with you and listed in Schedule A. They are typically your existing cloud account and your existing business systems, plus a model provider. Ask and we will name every one in writing.

Your own obligations

Where your industry imposes rules on us as a vendor, we will sign to them or tell you plainly that we cannot. We will not sign something we cannot honour.

03 / AI Usage & Ethics

AI Usage & Ethics

Human in command

This is the product, not a disclaimer. Agents prepare, draft, route and surface. A named person approves anything that leaves your business or moves money. The dashboard is built around that approval step.

Model choice

Chosen per engagement and named in Schedule A. If you require a specific provider, or require that a class of data never reaches a model at all, that is a scoping decision we make with you before building.

Training

Your data is not used to train models. We use providers on terms that exclude customer data from training, and we do not build training sets from client work.

Error handling

Agents are built to fail closed. An agent that cannot complete a step stops and escalates rather than guessing, and every action is attributable to the agent that took it.

What we will not claim

Convoy has no shipped builds yet. Nothing on this site is a delivered client result, and the dashboards are illustrative and labelled as such. When we have outcomes worth showing, we will show the real ones.

Scope honesty

If a CIS does not earn its place in your operation, the recon will say so. That is a real outcome of a recon, not a courtesy line.

04 / The Engine

Built on Claude.

The reasoning inside a CIS is not something we wrote. It is Anthropic's Claude, the same engine we build the system itself with — which means the hardest part of the stack is one we inherit rather than improvise.

Convoy Automation
Claude
Code
Anthropic's AI engine

Why the engine is part of the trust answer

  • It is not a homegrown model. A small build firm writing its own reasoning layer would be the least trustworthy thing on this page. Anthropic is an established AI safety company, and their safety and security programme is one we inherit rather than reinvent.
  • Your data is not training data. We work with model providers on commercial terms that exclude customer data from training, and the specific provider for your engagement is named in Schedule A before anything is built.
  • Claude is built to decline and to flag doubt. Anthropic trains it to refuse work it should not do and to say when it is unsure rather than guess. When an agent is near your money and your customers, a model that stops is worth more than a model that is confident.
  • It matches how a CIS is designed to run. Anything that moves money or leaves the building stops in the command queue for a human. That control is ours; a model that surfaces uncertainty instead of acting on it is what makes the control work in practice.

Built on Claude is a statement of what we run, not a partnership, endorsement or certification by Anthropic. As everywhere else on this page: what we inherit, we call inherited.

Frequently Asked Questions

Sixteen questions, answered plainly.

Where your data lives, who can reach it, what we hold versus what we inherit, which models we use, and exactly how far along Convoy actually is. Where the answer is no, it says no.

Deploy

Still have a question?

Send us your security questionnaire and we will complete it directly, or book a recon and ask on the call.

Email us? Click here

Book a call

Thirty minutes, no cost, no obligation. Bring the questionnaire.

Book the recon call Or send the brief first →