Conveyor Inc.

Conveyor Inc.

Search the Trust Center...
Ctrl +K

Conveyor Inc. | Trust Center

Everything you need to complete your security review is here. Browse documents, certifications, and compliance details with confidence. Our Trust Center is regularly updated to reflect the latest audit results, and subprocessor disclosures.

Badges

soc2-type-2
SOC 2 Type II

Documents & Knowledge Base FAQs

Quick Summary

One or more annual third-party audit(s)

Has a formal mobile device management (MDM) program

Annual third-party penetration testing

Has a disaster recovery plan

Subprocessors list available

Has cyber insurance

Deletes customer data on request

Uses a centralized IAM solution (SSO) to manage employee access

Featured Documents

Subprocessors of user personal data27

Subprocessor
Location of Processing
Usage Details
Anthropic

Anthropic

United States*
LLM provider
Aptible

Aptible

United States
Cloud Infrastructure
Atlassian Statuspage

Atlassian Statuspage

United States
Communicating system status to users.
AWS

AWS

United States
Cloud Services
Chameleon

Chameleon

United States
In app guides
Datadog

Datadog

United States
Logging and Monitoring
dbt Labs

dbt Labs

United States
Data Warehouse
Descope

Descope

United States
Authentication and user management
Elastic

Elastic

United States
Keyword search
FullStory

FullStory

United States
User Behavior Analytics
Google Cloud

Google Cloud

United States*
- Cloud Infrastructure - LLM Provider
Google Workspace

Google Workspace

United States
Customer Support
Hevo

Hevo

United States
Data warehouse synchronization
Knock

Knock

United States
Notifications
LangChain

LangChain

United States
Debugging, testing, and monitoring ConveyorAI performance.
Linear

Linear

United States
Support Subprocessor: Will process the contents of your support requests
Liveblocks

Liveblocks

United States
Real-time collaboration
Looker

Looker

United States
Analytics
OpenAI

OpenAI

United States*
LLM provider
Paragon

Paragon

United States
Conveyor integrations
Postmark

Postmark

United States
Email
Pylon

Pylon

United States
Support Subprocessor: Will process the contents of your support requests
Slack

Slack

United States
Communication and Customer Support
Snowflake

Snowflake

United States
Data warehouse.
Svix

Svix

United States
Optional subprocessor. Svix provides webhooks-as-a-service. If enabled, the payload of your webhook will flow through and temporarily be stored on Svix servers in the USA.
Zapier

Zapier

United States
Workflow Automation
Zoom

Zoom

United States
Virtual Meetings and Customer Support
Last updated . .
View as:

Third-Party LLM Providers

*Storage of Customer Content by these sub-processors, where applicable, occurs in the United States. Inference requests may be transiently routed through the provider's global network to improve latency and availability; such processing is ephemeral and no Customer Content is stored at rest outside the United States.

Conveyor relies on Third-Party LLM and Vector Embedding Providers to deliver parts of ConveyorAI. The following Third-Party LLM Providers are presently utilized:

LLM Providers

  • OpenAI
  • Anthropic
  • Google

Vector Embedding Database

  • Pinecone

The contents of your Conveyor Knowledge Base, documentation, and questionnaires is processed by these Third-Party LLM and Vector Embedding Database Providers in accordance with the agreement(s) in place between our organizations.

Announcements

API Key Security Enhancements

This announcement is to let you know about two important security improvements to the Conveyor API. Adoption of the Conveyor API continues to increase, especially as we add additional features like updating the Knowledge Base or gathering raw data for reporting. Additionally, our recently launched MCP server can use API keys which introduces more considerations for properly scoping what you are granting access to.

API Key Visibility:
Previously, when adding an API Key to Conveyor, we would allow admin users to view the key after it was created. We have implemented a security enhancement to only show the key once at time of creation. After that, you will only be able to view the first right characters of a created key.

API Key Granular Permission:
Each API key you generate can now be associated with Read/Write/Delete permissions, as applicable, across the different possible API scopes. This enables you to enforce the principle of least privilege with API keys you generate, as well as ensure newly added APIs are not in scope by default.

To get the full benefit of these security improvements, we recommend you regenerate existing API keys. This will reduce the risk that a key was viewed by other admins after being created as well as allow you to rescope the key to have only the least privileges required for your specific use case.

Thanks for your continued feedback on our API offering.

Conveyor Privacy Statement Update

We're updating our Privacy Statement with clarifications on how we manage our wider business operations and our relationship with customer administrators, including expanded disclosure on meeting recordings. Existing DPAs and commercial agreements are unchanged. You can review the updated policy here.

2023 SOC 2 Type II

The Conveyor 2023 SOC 2 Type II is now available for your review. The audit was completed by Linford & Company LLP, covers a period from 1/1/2023 to 12/31/2023, and includes the trust services criteria for Security, Availability, and Confidentiality.

New year, new status page

We're excited to enter 2024 with a new and improved status page! Check it out and subscribe to updates here: https://status.conveyor.com/.

2022 SOC 2 Type II

Our 2022 SOC 2 Type II is now available for review in our Conveyor Room. The audit was completed by Linford & Company LLP, covers a period from 1/1/2022 to 12/31/2022, and includes the trust services criteria for Security, Availability, and Confidentiality.

No impact from the March 22 Okta/LASUS$ incident

As the news of the Okta security incident broke, we reviewed our Okta usage logs and user configurations. We see no indication that any of our data or user accounts were affected. Further, we are not in the 2.5% of customers that Okta has identified and contacted as being potentially affected by this incident. We will continue to closely monitor the situation and work with our key suppliers to understand the extent of any exposure.

SCIM in Conveyor is here!

Conveyor users on the Growth tier or higher can now manage user assignments to Conveyor entirely through Okta or other identity providers rather than needing to manage invitations in-app. You can additionally manage your users' roles via the SCIM Group functionality. We recommend enabling SCIM to make managing user access easier and less error-prone.

Updated PenetrationTest Available

Our 2022 penetration test summary is now available for authorized users in our Conveyor Room.

What we offer

Conveyor

Conveyor is a network for sharing trust documentation with customers and prospects. Companies can also use the platform to complete security reviews of all of their vendors.

Typical data access: Business confidential (SOC 2, customer list, revenue data [optional]), Basic personal data (full name, business email)

Certifications: SOC 2 Type 2

Trusted by

Alteryx Trust Center
Atlassian
Carta
Clari/Salesloft
dbt Labs
Lucid Software
Productboard
Sumo Logic
Zapier
Powered by Conveyor, the first end-to-end customer trust platform.
Learn more