Security at Praxivara

You hand it the keys. We earn that.

Praxivara takes real action across your inbox, CRM and finances — and builds AI agents to run the work. That only matters if it's locked down properly. Here is exactly how your data and your accounts stay protected, end to end.

  • Fernet encryption at rest
  • TLS in transit, everywhere
  • OAuth — never your passwords
  • Email + TOTP 2FA & backup codes
Praxivara · how your data is stored
Plaintext · in memory only
"Acme renewal at $48,000 — close by Friday."
Fernet · AES-128-CBC + HMAC
Stored in the database
gAAAAABl9c2k7n3xR2pQ8sVtZ1mYw4fK6jLhB0a…
In transit · TLS 1.2+ with HSTS enforced
Defense in depth

Security built into every layer.

Praxivara handles your most sensitive systems, so protection isn't bolted on at the end — it's the foundation. From the bytes at rest to the actions it takes on your behalf, control stays with you.

Encryption

Encrypted at rest with Fernet, in transit with TLS.

Two independent layers protect your data. At rest, sensitive fields are sealed with Fernet symmetric encryption at the application layer — so even direct database access reveals nothing readable. In transit, TLS protects every byte between your browser, our servers, and the tools you connect.

  • Fernet (AES-128-CBC + HMAC) on chat, notes, memory & secrets
  • Encryption applied before the write — not after
  • TLS everywhere, with HSTS to prevent downgrade
  • Generated files stored as references, not exposed blobs
OAuth connections

OAuth, never passwords.

We connect to Gmail, Outlook, Google Workspace, your CRM, accounting and storage through OAuth. We receive a scoped, revocable token — and never see, store, or transmit your third-party passwords.

  • Scoped tokens — each integration gets only what it needs
  • Revoke access by disconnecting; it cuts off immediately
  • No third-party passwords ever stored or transmitted
  • Every connected tool uses the same OAuth model
2FA & sessions

Two-factor by choice. Sessions under control.

Harden your account with email codes or a TOTP authenticator, and keep one-time backup codes for recovery. From Settings → Security you can see every device signed in — and revoke any of them instantly if a laptop goes missing or a session looks unfamiliar.

  • Email OTP and TOTP authenticator apps
  • One-time backup codes for recovery
  • Per-device session list with location & last-seen
  • Revoke a single session — or sign out everywhere
Audit logs

A full trail of everything that happens.

Sign-ins, security changes, and the actions your assistant and AI agents take are recorded in an activity trail. Nothing happens behind your back — you can always read back exactly what was done, when, and by which agent.

  • Sign-ins and security changes recorded
  • Every assistant and agent action captured
  • Audit details encrypted at rest
  • Readable activity trail you can review anytime
Rate limiting

Abuse and brute-force, blunted.

Authentication and action endpoints are rate-limited to blunt brute-force attempts and runaway automation. New-device sign-ins are flagged, and unusual activity is surfaced so you notice it early — across every channel your assistant runs on.

  • Rate limits on auth and action endpoints
  • New-device sign-ins flagged for you
  • Runaway automation throttled automatically
  • Same protection across web and phone channels
Data deletion

Your data is yours to remove.

These rights are built into the product, not buried in a policy. Delete individual conversations, disconnect any integration to cut off its access immediately, or request full account erasure — your choice, at any time.

  • Delete individual conversations instantly
  • Disconnect any tool to revoke its access
  • Request full account erasure anytime
  • No lock-in — take your data with you
Account protection

2FA on. Sessions in your hands.

Add a second factor, keep backup codes for recovery, and see every device signed in to your account. If a laptop goes missing or a session looks unfamiliar, revoke it in one tap — or sign out everywhere at once.

  • Email OTP and TOTP authenticator apps
  • One-time backup codes for recovery
  • Per-device list with location & last-seen
  • Revoke one session — or all of them
Settings · Security
Two-factor authentication
TOTP authenticator · 8 backup codes left
On
Active sessions
MacBook Pro · Chrome
San Francisco, US · now
This device
iPhone · Praxivara app
New York, US · 2h ago
Control & accountability

It acts on your behalf — on your terms.

Praxivara takes real action across the tools you connect. Sensitive work is gated behind approval cards, scoped to the permissions you grant, and written to an audit trail you can always read back.

Confirmation required · Stripe
Approve before anything leaves your account
ActionPayout
Amount$1,840.00
ConnectionOAuth · revocable

Confirmation-gated actions

Sends, payments and anything customer-facing surface as an approval card showing the tool, recipient and amount. Nothing leaves until you tap Approve.

Scoped, revocable access

Each integration grants only the OAuth scopes it needs. Disconnect any tool and access is cut off immediately.

Full audit trail

Security-relevant events and every assistant or agent action are captured in an activity trail you can review anytime.

Abuse protection

Auth and action endpoints are rate-limited to blunt brute-force and runaway automation, with new-device sign-ins flagged.

AI sub-processors

Your data is not used to train models.

Praxivara's auto-router sends each request to the right model for the job, drawing on a small, carefully chosen set of AI providers. Every one is contractually restricted from training on your data, and we send only what's needed to complete the request you asked for.

  • No training on your private conversations or business data
  • A minimal provider set, each bound by strict data terms
  • Only the data needed for the task is ever sent
See the full subprocessor list
Provider
What we use it for
Trains on your data
Anthropic
Claude models — chat, reasoning & tool use
No
OpenAI
Models, transcription, synthesis & images
No
Google · Gemini
Gemini models & cloud AI services
No
Routed automatically per request — frontier intelligence for hard reasoning, fast models for routine work.
Data deletion & erasure

Your data is yours to remove.

These rights are built into the product, not buried in a policy. Take your data with you, or remove it entirely — on your schedule, not ours.

Access your data

See the information tied to your account whenever you need it.

Export anytime

Take your conversations and data with you — no lock-in, ever.

Delete & erase

Remove conversations instantly, or request full account erasure.

Revoke access

Disconnect any integration and cut off its access immediately.

Our promise

The lines we refuse to cross.

Security isn't only about what we build — it's about the things we will never do, no matter what.

  • Sell or rent your data to anyone
  • Train AI models on your private conversations
  • Store your third-party account passwords
  • Take sensitive actions without your approval
  • Share data between separate accounts
  • Hide what the assistant did from you

Found a vulnerability?

We take security reports seriously and respond quickly. If you believe you've found a vulnerability, please reach out privately first — responsible disclosure keeps everyone safe, and we'll work with you through to a fix.

  • Acknowledged promptly
  • Updated through resolution
  • Researchers credited
FAQ

Security, in plain terms.

Does Praxivara store my third-party passwords?
Never. Every connection — Gmail, Outlook, your CRM, accounting, storage — is made through OAuth. We receive a scoped, revocable access token and never see, store, or transmit the password to your other accounts.
How is my data encrypted?
Sensitive stored data — chat content, notes, agent memory and secrets — is encrypted at the application layer with Fernet (AES-128 in CBC mode with HMAC authentication) before it reaches the database. All traffic is served over TLS, so data is encrypted in transit too.
Do AI providers train their models on my data?
No. Our AI sub-processors are contractually restricted from training their models on your data. Praxivara sends only what is needed to complete the request you asked for.
Can I see and revoke active sessions?
Yes. Settings → Security lists every device and browser signed in to your account, with the location and last-seen time, and you can revoke any session — or all of them — instantly.
What 2FA options do you support?
Email one-time codes and TOTP authenticator apps (Google Authenticator, 1Password, Authy, and others), plus one-time backup codes to recover access if you lose your device.
Can I delete my data?
Yes. You can delete individual conversations at any time, disconnect any integration to cut off access immediately, and request full account erasure through our contact page.

Want the full picture? Visit the Trust Center or read our Privacy Policy.

Hand over the busywork, not the control.

Encryption at rest and in transit, OAuth-only connections, 2FA, audit logs, and your approval on anything sensitive — built in from day one. Start your 7-day free trial.

7 days free • Cancel anytime • Nothing charged until your trial ends