Security

Security, stated plainly.

What Ketvia does today to keep your workspace under your control, and what is still on the way. Facts only, no badges.

Roles

Every workspace has four roles. Admin screens, bot settings and source connections are limited to owners and admins.

Audit log

Admin actions are written to an audit log: who did it, what changed and when. Owners and admins can review it in the admin area.

Two-step verification

Turn on two-step verification with any authenticator app (TOTP). You get ten one-time recovery codes, and each works only once.

Passkeys are planned.

Export and retention

Export your own data; admins can export the workspace. Exports are encrypted and can be downloaded for 24 hours. Owners choose how long messages and attachments are kept, from 30 days to 10 years.

Retention per channel is planned.

Separate workspaces

Each workspace opens on its own address. Workspace data is separated in the database with row-level security, so one workspace can’t read another’s.

Encrypted connections

All traffic uses HTTPS with strict transport security, and session cookies are marked secure. Credentials for connected sources are encrypted with a server key before they are stored.

Assistant permissions

The assistant reads only the sources an admin has connected, answers only in channels where it is allowed, and never applies a change without approval from the person who asked.

How the assistant works

Privacy

The early-access list has its own privacy notice describing what we collect and why. Inside the app, a data transparency page explains how workspace data is handled.

Privacy notice (Turkish)

On the way

Ketvia doesn’t hold third-party security certifications yet, and we don’t claim any. These features are planned and not built:

Single sign-on (SAML / OIDC) · Coming soonSCIM provisioning · Coming soonPasskeys · Coming soonRetention per channel · Coming soon

Questions about security?

Write to [email protected].

Request early access