Trust & Data Protection

Security & Data Privacy

How VartAI — operated by XRaise Solution — protects your data and the data of the leads you manage. We describe only what we actually do today.

◆ Data stored in Canada · Toronto · Last updated 8 July 2026

Stored in Canada

Managed PostgreSQL in a Toronto region on SOC 2 / ISO 27001-certified infrastructure.

Encrypted end to end

TLS in transit; encrypted at rest by the managed database.

Hardened passwords

Hashed with PBKDF2-SHA256 — never stored in plain text.

No card data held

Card details go straight to Stripe — never to our servers.

01

Where your data lives

Your data is stored in Canada. The primary production database is a managed PostgreSQL instance hosted in a Toronto region, on infrastructure that is SOC 2 Type II and ISO 27001 certified. Lead records, conversation history, meetings, and account data reside there. The scheduling database is hosted in the same Toronto region.

Cross-border processing, stated plainly: to deliver messages and provide AI features, some data is processed by trusted third-party service providers, several of which are based in the United States — so message content sent to them for delivery or analysis may be processed outside Canada. Data at rest in VartAI's own systems stays in Canada. A current list of these providers is available to customers on request.

02

Encryption

  • In transit: all application traffic is served over HTTPS (TLS). Application-to-database connections require TLS with certificate verification.
  • At rest: the production database is encrypted at rest by the managed database provider.
03

Authentication & access control

  • Passwords are hashed with PBKDF2-SHA256 before storage — never kept in plain text.
  • Sessions use signed JWT access tokens.
  • Single sign-on via Google and Microsoft, restricted to allow-listed email domains; new SSO users stay inactive until an administrator approves them.
  • Every user is scoped to their own company account (see section 06).
04

Payment security

Billing uses Stripe. Card details are entered directly into Stripe's own hosted fields (against a Stripe SetupIntent) — raw card numbers never reach VartAI's servers, keeping card data out of our systems. We store only a Stripe customer reference and non-sensitive metadata (card brand, last four digits, expiry).

05

Webhook & integration authenticity

Inbound webhooks from our messaging, voice, scheduling, and billing providers are cryptographically verified — via request signatures or shared secrets — before we act on them. Unverified requests are rejected.

06

Multi-tenant isolation

VartAI is multi-tenant. Every lead, message, and meeting is scoped to the owning company, and lookups are constrained to the authenticated user's company at the database-query layer — cross-tenant access is rejected. Inbound messages and calls are resolved to the correct company by the destination phone number before any lead is matched.

07

What data we process

  • Account data — your team's names, emails, roles, and authentication material.
  • Lead data — name, email, phone, company, and any notes/attributes you provide.
  • Conversation data — SMS and email content, voice-call transcripts and recordings, timestamps, delivery status.
  • AI-derived metadata — sentiment, intent, and similar classifications used to route and personalize outreach.
  • Scheduling data — booked meeting times and related calendar details.
  • Billing data — usage counts and the Stripe references from section 04.
08

Integrations you control

CRM and calendar integrations — Zoho, Salesforce, HubSpot, and Google Calendar — are optional and activated by you via OAuth. VartAI accesses them only with the permissions you grant, and only to sync the leads, conversations, and scheduling relevant to your account. You can revoke access at any time.

09

Credential & secret handling

  • Provider API keys and secrets live in the deployment environment and CI secret stores — never committed to source control.
  • Access to third-party systems uses scoped credentials and tokens.
10

Reliability & monitoring

  • The managed database provider performs automated daily backups.
  • Application errors are monitored continuously, with alerting to the VartAI team.
  • A master control can immediately pause all real outbound messaging for maintenance.
11

Data retention & deletion

  • Accounts and companies use soft deletion — data is marked deleted, becomes inaccessible, and remains recoverable for a limited window before permanent removal.
  • Lead records can be permanently deleted on request; their messages and meetings go with them.
  • Retention: we retain customer and lead data for up to 6 years, in line with common Canadian financial record-keeping expectations, after which it is eligible for deletion. We honour a verified export or deletion request within 30 days.
12

Your privacy rights

Depending on your jurisdiction (e.g. PIPEDA in Canada, GDPR in the EU/UK), you and your leads may have rights to access, correct, export, or delete personal data. VartAI supports these requests.

  • Privacy requests: security@vartai.ai — we verify the requester and respond within 30 days.
  • A signed Data Processing Agreement (DPA) and a current list of sub-processors are available on request for business customers.
13

Incident response

If a security incident affecting customer data occurs, VartAI will investigate, contain, and remediate it, and notify affected customers without undue delay, and within 72 hours of confirming a breach, at the security contact below.

Security contact

Report a vulnerability or request our DPA / sub-processor list at security@vartai.ai.