Security and trust

Built for audit from the first day

Convoy exists for work that has to be right and has to be provable. Here is concretely how we treat your organization, your people, and your records.

Your organization stands alone

Every record in Convoy belongs to exactly one organization, and that boundary is enforced in the database on every query, not just in the interface. There is no path where a request from one organization reads another organization’s data.

When Convoy staff help operate a routine inside your organization, they act under a named account with a defined role, and everything they do lands in your audit trail exactly as your own team’s actions do.

Four roles, checked on the server

Access follows a small set of roles, and every action is checked on the server, never just hidden in the interface:

  • Admin

    Manages people, policies, budgets, and billing for the organization.

  • Operator

    Runs and promotes routines, manages workspaces and systems.

  • Member

    Works with assigned routines, answers checkpoints, gives feedback.

  • Viewer

    Read only. Built for external reviewers and audit firms who need to see the record without being able to touch anything.

An audit trail with names in it

Every step a routine takes, every plan approved, every checkpoint answered, and every administrative change is recorded with who did it and when. Approvals are individual acts by named people; there is no anonymous yes.

When a checkpoint is assigned to a team, the person who answers is the person on the record. Attribution survives all the way into the evidence you export.

This website never holds your keys

The credentials that connect Convoy to your systems are never stored in the website or its database. The website holds only references; the secrets live in a separate, locked-down layer, and they never appear in logs, exports, or anywhere a person could casually read them.

Evidence binders, not screenshots

Any run can be exported as an evidence binder: the files it produced, a manifest of what happened, and checksums so the contents can be verified later. It is a single archive you can hand to an auditor without editing a thing.

A straight answer on certifications

We are built for audit, and we hold ourselves to the practices above, but we will not decorate this page with badges we have not earned. If a formal certification matters to your review, ask us directly and we will tell you exactly where we stand and what our roadmap is.

Put your hardest questions to us

Bring your security review. We would rather answer it early than impress you late.