Security & Trust Center
Enterprise-grade architecture, data privacy safeguards, and strict AI operational boundaries designed to protect your business and customer relationships.
1. Security Architecture
At Servn, security is not an afterthought or an add-on; it is engineered into the foundation of our platform. We understand that service businesses—from high-volume roofing contractors to multi-location solar installers—trust us with their customer records, proprietary quotes, and real-time caller audio.
AES-256 / TLS 1.3
End-to-end data encryption across all layers
Zero-Training AI
Customer data is never used to train public LLMs
99.9% Uptime SLA
Redundant multi-region cloud infrastructure
2. Data Encryption (Rest & Transit)
We implement industry standard cryptographic controls across the entire data lifecycle:
- Encryption in Transit: All communications between your devices and Servn are secured using Transport Layer Security (TLS 1.3 or TLS 1.2). We enforce HTTP Strict Transport Security (HSTS) with preloading to prevent downgrade attacks.
- Encryption at Rest: All databases, document stores, call recording audio, and encrypted backups are secured using Advanced Encryption Standard with 256-bit keys (AES-256).
- Cryptographic Key Management: Keys are managed through AWS Key Management Service (KMS) with automatic annual key rotation and strict IAM separation of duties.
3. AI Model Safety & Privacy Boundaries
When utilizing ServnAssist for AI-driven phone calls, lead qualification, and scheduling:
Zero Retention & Zero Public Training Guarantee
Servn operates on dedicated enterprise AI inference contracts. None of your customer calls, voice transcripts, form submissions, or CRM data are retained by third-party model providers to train foundation models.
Prompt boundaries and strict system instructions ensure that conversations cannot be manipulated or prompted to disclose sensitive proprietary company information.
4. Cloud Infrastructure & Uptime
Servn is hosted on top-tier hyperscale cloud infrastructure (Amazon Web Services and MongoDB Atlas Cloud):
- High Availability & Redundancy: Distributed across multiple availability zones with automated failover.
- Continuous Automated Backups: Point-in-time recovery (PITR) backups taken continuously with encrypted geographical replication.
- DDoS Mitigation & Web Application Firewall: Advanced perimeter filtering blocks volumetric DDoS attacks, SQL injection attempts, and cross-site scripting (XSS).
5. Access Control & Authentication
- Multi-Factor Authentication (MFA): Mandatory two-factor authentication available for all organization accounts.
- Role-Based Access Control (RBAC): Granular permission tiers (Owner, Administrator, Dispatcher, Technician, Viewer) so staff only access relevant information.
- Least-Privilege Internal Access: Servn engineers do not possess direct access to customer databases in production. Any emergency administrative access requires cryptographic multi-party authorization, short-lived tokens, and comprehensive audit logs.
6. Compliance & Governance
- GDPR & CCPA/CPRA Compliant: Built-in tooling for automated data export, rectification, and right-to-be-forgotten deletion workflows.
- PCI-DSS Level 1: Credit card processing is handled entirely via Stripe Elements and secure tokenization; Servn servers never touch, store, or transmit raw credit card numbers.
- TCPA / CTIA Compliance: Strict consent logging for SMS and automated telephony calls.
7. Monitoring & Incident Response
We maintain an active Security Incident Response Plan (SIRP). Our infrastructure triggers real-time alerts for anomalous API usage, failed authentication spikes, and unauthorized configuration alterations.
In the event of a confirmed security incident affecting customer data, Servn will notify affected account administrators within 72 hours in compliance with statutory obligations.
8. Vulnerability Disclosure
We welcome vulnerability reports from independent security researchers. If you believe you have found a security vulnerability in Servn:
Responsible Disclosure Guidelines:
Please email details to [email protected]. Include reproducible steps and proof-of-concept code. We ask that you give us reasonable time to investigate and remediate the issue prior to public disclosure.
Ready to build a better service business?
Capture more leads. Respond faster. Close more customers. Spend less time on repetitive work.
