Built for regulated industries.
Secured like it.

SVA handles sensitive conversations in healthcare, finance, legal, and insurance. Security isn’t a feature—it’s the foundation everything else is built on.

GDPR

CCPA

LGPD

PIPEDA

Security architecture at a glance

Your data stays yours

BYOAPI architecture means conversations flow through your API keys. We don't store or access your AI provider data.

Encrypted everywhere

256-bit encryption for data at rest. TLS 1.3 for data in transit. API keys salted and hashed.

Global privacy compliance

Built-in consent handling for GDPR, CCPA, LGPD, and PIPEDA. PII scrubbing before storage.

Complete audit trail

Every conversation, every action, every security event logged and exportable for compliance review.

Where your data lives—and doesn't

What we store

What we don't store

BYOAPI Architecture

When visitors talk to SVA, requests go directly to your AI provider using your API keys.

We route the request, but the AI processing happens on your account.

This means: Your rate limits. Your usage dashboard. Your data relationship with the provider.

We can’t see your AI conversations because they’re not ours to see.

Privacy by design

GDPR (Europe)

CCPA (California)

LGPD (Brazil)

PIPEDA (Canada)

Need a specific compliance document? Contact us.

Sensitive data gets scrubbed

Standard Mode

Strict Mode

For industries with heightened sensitivity requirements.

You choose the mode. SVA enforces it automatically.

Encryption everywhere

Data at Rest

Data in Transit

Key Management

You choose the mode. SVA enforces it automatically.

Who can access what

Your Team

Admin: Full configuration access, conversation review, guardrail management

Manager: Conversation review, analytics, limited configuration

Viewer: Read-only conversation access

Role-based permissions configurable per installation

Our Team

AI Providers

Stopping bad actors before they start

Rate Limiting

Bot Detection

Threat Monitoring

Automatic response: throttle → block → ban

Jailbreak Prevention

Receipts for everything

Security Events Logged

Conversation Logging

Compliance Reports

Guardrails aren't just compliance—they're security

Constitutional AI prevents your assistant from being manipulated into harmful responses.

Unlike prompt-based instructions, constitutional rules can’t be jailbroken.

Even if a bad actor tries to trick SVA into giving medical advice, legal counsel, or financial recommendations—it physically can’t.

Your brand is protected. Your liability is reduced. Your compliance team sleeps better.

Where SVA runs

Hosting

WordPress Plugin

Backups

If something goes wrong

We maintain an incident response plan for security events.

Affected customers notified within 72 hours of confirmed breach.

Post-incident reports available for significant events.

Security contact: security@simpleaisystem.com

Documentation for your team

Data Processing Agreement (DPA)

Security whitepaper

SOC 2 report (in progress)

Privacy policy

Terms of service

Subprocessor list

Need something specific? Contact us and we’ll provide it.

Want us to handle it?

Do you train AI models on my conversation data?
No. Your conversation data is never used to train any AI models. It stays in your account for your use only.

.

Conversation data is stored in encrypted cloud infrastructure. Your AI provider data is governed by your relationship with that provider (OpenAI, Anthropic, etc.).
Not by default. Support access requires your explicit permission, is logged, and is revoked after the session.
All your data is permanently deleted within 30 days. We can expedite on request.
We are pursuing SOC 2 Type II certification. Contact us for our current security documentation.
We follow industry-standard incident response. Affected customers are notified within 72 hours of confirmation. Full post-incident reports provided.
Yes. Contact us to schedule a security review call or request our security questionnaire responses.
SVA is designed with HIPAA-aligned controls: encryption, access controls, audit logging, and consent handling. For covered entities, we can execute a BAA (Business Associate Agreement). Contact us to discuss your specific requirements.

Questions about security?

Our team is happy to walk through security requirements with your compliance or IT team.