Security
Last updated September 15, 2026
This page describes our current practices as an early-stage company and will expand as our program matures. It has not yet been reviewed by counsel.
Our approach
Sarvex sits close to merchant checkout and catalog data, so we treat security as a first-class requirement, not an afterthought. We're an early-stage company and don't yet hold third-party certifications — this page describes the practices we follow today and will be updated as our program grows.
Data handling
Data is encrypted in transit (TLS) between your store, Sarvex, and the agent surfaces we integrate with. Access to production systems and customer data is limited to the team members who need it to operate the Service, and is logged.
Infrastructure
The Sarvex website and dashboard run on reputable managed cloud infrastructure. We keep dependencies patched and monitor for known vulnerabilities in the libraries we rely on.
Access and authentication
Dashboard access is protected by account authentication, and we scope internal access to the minimum needed for each team member's role.
Responsible disclosure
If you believe you've found a security vulnerability in Sarvex, please tell us before disclosing it publicly. Email security@sarvex.io with steps to reproduce the issue. We'll acknowledge reports promptly and keep you updated as we investigate and fix confirmed issues.
Contact
For anything else security-related, reach us at security@sarvex.io or through our contact page.