
Enterprise customers rightly ask hard questions about security before trusting any platform with their call data and customer information. Here's how Onvea approaches it — honestly, without overclaiming.
Data Encryption
All data is encrypted in transit and at rest:
Access Controls
Compliance Posture
Onvea is a small, growing company. We take compliance seriously and have designed the platform with privacy-first principles, but we want to be upfront about where things stand:
GDPR
Our data handling is designed around GDPR principles — data minimization, purpose limitation, and support for right-to-erasure requests. If you need a Data Processing Agreement, contact us at admin@onvea.co.
HIPAA
If you're in healthcare, you should know that Onvea is not currently a HIPAA Business Associate and does not offer a BAA. Healthcare organizations handling PHI should consult with their compliance team before using any AI calling platform, including ours. We're actively working toward a formal HIPAA readiness program — this is on our roadmap.
SOC 2
We have not yet completed a SOC 2 audit. This is on our product roadmap as we scale. If SOC 2 certification is a hard requirement for your organization, reach out and we can discuss timeline and interim controls.
What We Recommend
We'd rather be honest about where we are today than make claims we can't back up. Questions? Email us at admin@onvea.co.