Savra

Security & trust at Savra

How we handle your data, your Google connections, and your brand. Written for the person who has to sign off on us.

How we protect your data

Six things worth checking before you connect an account

Each of these is either shipped today or explicitly marked as planned. We would rather lose a deal than misrepresent a control.

Live

Multi-tenant isolation

Every company’s data is scoped to its own tenant. The knowledge base a chatbot answers from is tenant-scoped, so one customer’s content can never surface in another’s output.

Live

First-party OAuth

You connect GA4, Search Console, and Google Ads with your own account and your own scopes, and you can revoke any of them from your Google account. Savra reads live data through the API — it never scrapes screenshots or asks for your password.

Live

Data minimization

We request the narrowest scope that makes a feature work, and read-only wherever reading is enough. If a scope is not needed for something you turned on, we do not ask for it.

Live

Encryption in transit and at rest

Traffic is served over TLS, and stored data is encrypted at rest. Credentials for connected accounts are stored encrypted, never in plain text.

Live

Payments handled by Stripe

Card details go to Stripe and are processed there. Savra never sees or stores a card number, so a Savra incident cannot expose your payment method.

Planned

SOC 2 Type II

Not yet held. It is a planned milestone with no committed date. Until it is real, this card stays marked Planned.

Google user data and the Limited Use policy

Savra’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

In plain terms, for the Google accounts you choose to connect:

  • We use the data only to provide the analytics, SEO, and ads features you turned on.
  • We do not use it to train models.
  • We do not sell it, and we do not share it with third parties for advertising.
  • Humans do not read it, except where you ask us to for support or where the law requires it.

How that data is handled end to end is set out in the privacy policy.

What each connection reads

Savra reads your Google data to build reports and recommendations. It does not change your configuration and it does not spend your budget. Two of the three Google connections use scopes that are read-only by construction; the third is described honestly below.

Google Analytics 4

  • Reads: sessions, traffic sources, conversions, and the property and stream configuration needed to interpret them.
  • Scope granted: read-only.
  • Why: so reporting reflects your real numbers instead of you pasting screenshots into a chat.

Google Search Console

  • Reads: queries, impressions, clicks, positions, and indexing status.
  • Scope granted: read-only.
  • Why: to ground SEO and AI-search recommendations in the queries you actually rank for.
  • Reads: campaign, ad group, and creative performance, plus account settings needed to score account health.
  • Scope granted: Google publishes exactly one OAuth scope for the Ads API and it is capable of both reading and writing. There is no read-only Ads scope to request instead, so we will not describe this one as read-only. Savra uses it to read.
  • How to enforce that yourself: give the connection a read-only role on the Google Ads account. Account permissions, not the OAuth scope, are what constrain writes at Google’s end.
  • Why: to run the ad health checks before you spend.

Social and messaging channels

  • Reads: the published-content and performance data for the channels you link.
  • Writes: publishing, and only to the channels you explicitly connect for publishing.
  • Why: to schedule and publish on your behalf and report back on what happened.

The exact scopes appear on the consent screen at the moment you connect an account. That screen is authoritative — read it before you approve. Each scope is also listed, with what it grants, in the privacy policy.

Subprocessors

We use a small set of third parties to deliver the service — model providers, vector storage, email sending, hosting. Each one, what it does, and where it processes data is listed at Subprocessors.

Compliance status

We are not SOC 2 certified and not ISO 27001 certified. Anyone telling you otherwise about Savra is wrong.

What is true today:

  • Least-privilege access, internally and for the scopes we request from you.
  • Tenant isolation for customer data and knowledge bases.
  • Compliance with the Google API Services User Data Policy, including Limited Use.
  • Encryption in transit and at rest.

SOC 2 Type II is a planned milestone. We are not committing to a date here, because a date on a trust page is a promise. If a certification is a hard requirement for your procurement process, tell us and we will be straight with you about where we are.

Reporting a vulnerability

If you have found a security issue, please tell us before you tell anyone else. Contact us with the details and a way to reach you, and mark it as a security report so it gets routed straight away.

We will acknowledge your report, keep you updated while we investigate, and credit you if you would like us to.

Security review

Questions we get from security reviewers

If your question is not here, ask it — we would rather answer directly than have you guess.

Running a formal review?

Send us your questionnaire and we will complete it, including the gaps.

Contact us

No. SOC 2 Type II is a planned milestone with no committed date. Today we operate on least-privilege access, tenant isolation, encryption in transit and at rest, and the Google Limited Use policy. We will tell you plainly where we are rather than point at a badge we do not have.

No. Savra reads performance data to build reports and recommendations. It does not edit your configuration, change campaigns, or spend budget. To be precise about the scopes behind that: Analytics and Search Console are granted through read-only scopes. Google publishes exactly one Google Ads API scope and it is read/write capable, so we will not call it read-only — Savra uses it to read, and you can enforce that at Google’s end by giving the connection a read-only role on the Ads account. Every scope is listed in the privacy policy.

No. Your content is used to produce your outputs and to keep them on-brand. It is not used to train models, and data received from Google APIs is never used for training under the Limited Use policy.

Customer data is scoped per tenant, including the knowledge base a chatbot answers from. A retrieval for one company is restricted to that company’s own content.

No. Payments are processed by Stripe. Savra never sees or stores a card number, so a Savra incident cannot expose your payment method.

Yes. The subprocessor list is public at /subprocessors, and a Data Processing Addendum is available at /dpa — contact us to put a signed copy in place for your account.

Ask us and we will export it or delete it. The retention detail, and the rights that apply where you live, are set out in the privacy policy.

Need a security review for your team?

Bring your questionnaire. We will walk your reviewers through how data flows, what we hold, and what we do not.