Skip to main content

Security at Intavia

This page summarises the controls Intavia uses to protect customer data. Last updated: 27 July 2026

Data hosting and encryption

Intavia’s primary production data is hosted in the AWS London region and is not publicly accessible. Customer data is encrypted in transit and at rest. Production credentials are protected and are not exposed to voice agents. In the standard voice-agent deployment, ElevenLabs processes call audio, transcripts, and related metadata in the United States. OpenAI may process transcript text and related call information in the United States. These transfers are governed by our Data Processing Addendum, including the EU Standard Contractual Clauses. Other provider roles and processing locations are listed on our Sub-Processors page.

Access and integration boundaries

  • Customer accounts use authenticated, organisation-scoped access controls.
  • Administrative access is restricted to authorised personnel according to operational need.
  • Practice-management and scheduling integrations expose predefined operations with validated inputs; they do not provide unrestricted access to the customer’s underlying system.
  • Where supported, customers can use dedicated integration users and provider permissions to limit access to the agreed workflows.

Infrastructure security and availability

Intavia uses web-application firewall rules, request authentication, source restrictions where appropriate, and rate limits to restrict access to expected systems and traffic.
  • The production database is configured for automatic failover.
  • Encrypted automated database backups are retained for 30 days and replicated to a second AWS region in the EU for disaster recovery.
  • The application layer scales automatically with demand.
  • Recovery procedures cover restoring core data and redeploying services.

Monitoring and development

  • Infrastructure and application health are monitored, with alerts for operational failures and security-relevant events.
  • Operational logging favours identifiers, status information, and sanitised diagnostics. Access to operational data is restricted.
  • GitHub Dependabot monitors application dependencies for known vulnerabilities and raises automated security updates where fixes are available.
  • Software changes are version controlled, automatically checked, and deployed through controlled workflows.
If a personal data breach affects a customer, Intavia will provide notification in line with the DPA and applicable law.

Assurance and due diligence

Provider assurance material is available through the AWS Compliance Programmes, ElevenLabs Trust Center, OpenAI Trust Portal, and Datadog Security Center. For a security questionnaire or supporting information, email andreas@intavia.ai with the customer name and service being reviewed.

Report a security issue

To report a suspected security vulnerability or incident, email andreas@intavia.ai with a description of the issue and the affected service. Please do not access customer data or disrupt the service while investigating.
Document owner: Intavia LTD
Security contact: andreas@intavia.ai