Security and trust
Built for audit from the first day
Convoy exists for work that has to be right and has to be provable. Here is concretely how we treat your organization, your people, and your records.
Your organization stands alone
Every record in Convoy belongs to exactly one organization, and that boundary is enforced in the database on every query, not just in the interface. There is no path where a request from one organization reads another organization’s data.
When Convoy staff help operate a routine inside your organization, they act under a named account with a defined role, and everything they do lands in your audit trail exactly as your own team’s actions do.
Four roles, checked on the server
Access follows a small set of roles, and every action is checked on the server, never just hidden in the interface:
Admin
Manages people, policies, budgets, and billing for the organization.
Operator
Runs and promotes routines, manages workspaces and systems.
Member
Works with assigned routines, answers checkpoints, gives feedback.
Viewer
Read only. Built for external reviewers and audit firms who need to see the record without being able to touch anything.
An audit trail with names in it
Every step a routine takes, every plan approved, every checkpoint answered, and every administrative change is recorded with who did it and when. Approvals are individual acts by named people; there is no anonymous yes.
When a checkpoint is assigned to a team, the person who answers is the person on the record. Attribution survives all the way into the evidence you export.
This website never holds your keys
The credentials that connect Convoy to your systems are never stored in the website or its database. The website holds only references; the secrets live in a separate, locked-down layer, and they never appear in logs, exports, or anywhere a person could casually read them.
Evidence binders, not screenshots
Any run can be exported as an evidence binder: the files it produced, a manifest of what happened, and checksums so the contents can be verified later. It is a single archive you can hand to an auditor without editing a thing.
A straight answer on certifications
We are built for audit, and we hold ourselves to the practices above, but we will not decorate this page with badges we have not earned. If a formal certification matters to your review, ask us directly and we will tell you exactly where we stand and what our roadmap is.
Put your hardest questions to us
Bring your security review. We would rather answer it early than impress you late.