Trust Center

An assistant with real access. Earned, then guarded.

Praxivara takes real action across your inbox, customers and finances — and builds AI agents that do the same. That power demands proof. This is the hub for exactly how we protect your data: encrypted, never sold, never used to train models.

Encrypted at rest & in transit OAuth-only — never your passwords Full activity audit trail
Praxivara · protected action Secure
Send the signed Vertex contract and pay their invoice.
Praxivara
Two sensitive steps — both need your sign-off before anything leaves your account:
Confirmation required
SendVertex-Contract.pdf
Pay$4,200.00 · QuickBooks
LoggedEither way
Our principles

Four promises we build the product around.

An assistant that can act across your business has to earn its access. These aren't lines in a policy — they're enforced in the product itself.

Your data is yours

You own everything you put into Praxivara. Export it whenever you like, delete it on request — no lock-in, no quiet retention, no surprises. The work it does belongs to you, full stop.

Encrypted, end to end

Encrypted at rest and in transit. OAuth-only connections mean we never see or store the passwords to your accounts.

Never sold

We don't sell, rent, or share your data across accounts. We send only what is needed to complete a request — nothing more.

Never used to train models

Your private conversations and business data are never used to train public AI models. The providers we route to are contractually restricted from training on your content.

Data handling

From the first connection to the last action.

Exactly how your data moves through Praxivara — whether the work is done by your assistant or an AI agent it built. Four stages, each with a guardrail.

  1. 01

    Connect via OAuth

    Grant scoped access in a couple of clicks. We receive a revocable token — never your password — and only the permissions you choose.

  2. 02

    Encrypted on arrival

    Anything stored is encrypted at rest before it lands in the database, and only ever moves over TLS in transit.

  3. 03

    Acted on with consent

    Routine reads run automatically. Anything sensitive — a send, a payment, anything customer-facing — waits behind a confirmation card you approve.

  4. 04

    Logged, then revocable

    Every action lands in your activity log. Disconnect any tool and the assistant — and its agents — lose access instantly.

Control, by design

Powerful enough to run the business. Guarded enough to trust it.

Praxivara takes real action across your tools — and it builds AI agents that do the same. The more it can do, the more it asks. Sensitive steps stop for your sign-off, and everything lands in your activity log.

  • See and export your data anytime — no lock-in
  • Delete conversations, or request full account deletion
  • Disconnect any integration to cut off access instantly
  • Every AI agent runs under the same gates and audit trail
Activity log · today
Read inbox · 4 threads
Auto · no approval needed
Built revenue report
Auto · file generated
Emailed Vertex contract
Approved by you · 9:14 AM
Paid Acme invoice · $4,200
Approved by you · 9:15 AM
Refund Globex · $980
Declined by you · logged
Infrastructure

Where your data lives.

A small, carefully chosen stack — so there are fewer places your data can go, and fewer ways anything can leak.

Isolated environments

Production runs in hardened, isolated infrastructure with least-privilege access between services.

Reputable cloud regions

Hosted on enterprise-grade cloud providers with strong physical, network, and access security.

Data minimization

We store only what is needed to run your assistant and its agents. Large files are kept as references, not raw blobs.

Sub-processors

Who processes your data.

The current list of third parties that may process data on our behalf — each bound by strict data-handling terms. We send only what's needed to complete your request, and we never sell your data.

Provider What they do for us Category
Anthropic Claude language models — chat, reasoning, and tool use AI models
OpenAI Language models, voice transcription & synthesis, image generation AI models
Google Cloud / Gemini Gemini language models and related cloud AI services AI models
Twilio Delivery of SMS and related messaging Messaging
Stripe Payment processing and subscription management Payments
Cloud hosting & database Running the application, database, and backend services Infrastructure
Object storage / CDN Storing and serving generated files and uploads Infrastructure
Email delivery provider Transactional and security emails (sign-in alerts, notifications) Communications
IP geolocation provider Approximate location from IP for new-device security Security

Full details — including how AI providers are restricted from training on your data — are in our Privacy Policy. This list may change as we add or replace vendors.

Compliance posture

Honest about where we are — and where we're going.

We design our controls around recognized frameworks and privacy law, and we'd rather be precise than overstate. Here's the current posture, plainly.

SOC 2-aligned controls

Our security program is designed around SOC 2 principles — access control, monitoring, and change management.

Privacy rights support

We support data access, export, and deletion requests in line with GDPR and CCPA expectations.

Audit logging

Security-relevant and administrative events are captured in an immutable audit trail.

Token rotation

OAuth tokens are refreshed and rotated automatically; revoked connections are invalidated immediately.

Our promise

Things we will never do.

Trust isn't only about what we build — it's about the lines we refuse to cross, even when it would be convenient not to.

Sell or rent your data to anyone
Train public AI models on your private data
Store your account passwords
Take sensitive actions without your approval
Share data between accounts
Hide what the assistant or its agents did from you
FAQ

Questions, answered.

Do you train AI models on my data?
No. Your conversations and business data are never used to train public AI models. The AI providers we route to are contractually restricted from training on your content.
Who can see my data?
Your messages and notes are encrypted at rest. We access data only as needed to operate the service you asked for, under least-privilege controls and an audited trail.
What happens when Praxivara takes an action across my tools?
Routine reads run automatically. Anything sensitive — sending email, moving money, anything customer-facing — surfaces as a confirmation card you approve or decline before it leaves your account.
What about the AI agents Praxivara builds?
Agents run under your assistant with the same guardrails: scoped permissions, approval gates on sensitive steps, and a full activity log of everything they do.
What happens if I disconnect an integration?
The OAuth tokens are revoked and invalidated immediately, and the assistant — and any agents — lose access right away.
Where is my data stored?
On enterprise-grade cloud infrastructure with isolated environments, encryption, and least-privilege access. We keep the stack small so there are fewer places your data can go.
Can I export or delete my data?
Yes. You can export your conversations and data anytime, delete individual conversations, and request full account deletion through our contact page.
How do you handle third-party providers?
We use a small, vetted set of infrastructure and AI sub-processors, each bound by strict data-handling terms. The current list is published below.

Still have questions? We're here.

Our team will walk you through our security, privacy and compliance practices in detail — and answer anything your vendor review needs.

Encrypted at rest · OAuth-only · Approval-gated · Export & delete anytime