Security at Suivo
Last updated: August 16, 2026
Suivo is a business platform for real estate teams. It handles customer relationship records, communications, calendars, tasks, files, and—when enabled—AI-assisted and voice features. We use technical, organizational, and administrative safeguards designed to protect that information. No online service can eliminate every risk, and we do not claim that Suivo is immune from error, attack, service interruption, or unauthorized access.
This page explains our current security approach in plain language. Contractual security commitments, if any, are set out in the applicable order form, data processing agreement, or other signed agreement.
What this page covers
This page covers the Suivo web application, mobile application, API, background workers, and the primary cloud infrastructure operated for the service. Third-party services connected by a customer—such as Google Workspace, Microsoft 365, telecommunications carriers, AI providers, or calendar providers—operate their own systems under their own security programs and terms.
Some safeguards are feature-dependent. For example, voice controls apply only when voice functionality is enabled, and mailbox controls apply only when a user connects a mailbox.
Shared responsibility
Security is shared among Suivo, each customer organization, its administrators, its users, and connected-service providers.
Suivo is responsible for safeguards within the systems it operates. Customer organizations are responsible for:
- choosing who may join their workspace and promptly removing users who no longer need access;
- assigning appropriate roles, record ownership, and connected accounts;
- protecting user devices, email accounts, identity-provider accounts, recovery methods, and credentials;
- using available multifactor authentication and device protections offered by their identity provider;
- reviewing integrations, permissions, and automated workflows before enabling them;
- obtaining all notices, consents, permissions, and lawful authority needed for personal information, email, SMS, calls, recording, transcription, and AI processing;
- respecting professional, brokerage, anti-spam, telemarketing, do-not-call, advertising, human-rights, and recordkeeping rules; and
- reporting suspected compromise to Suivo without delay.
Infrastructure and data location
Suivo's primary production application infrastructure is designed to run on Google Cloud. The reviewed deployment scripts default production application services to a Canadian Google Cloud region. Application data may be stored in managed database, object-storage, queue, cache, key-management, logging, and backup systems.
Canadian primary hosting does not mean that all processing remains in Canada. Depending on the enabled feature, information may be transmitted to or processed by providers in the United States or other countries, including authentication, connected email and calendar, AI, speech, telephony, transactional email, push-notification, and scheduling providers. Those transfers are described in the Privacy Policy. Data processed abroad may be subject to the laws of the jurisdiction where it is processed.
We do not describe Suivo as having complete Canadian data residency unless a signed agreement expressly defines the covered data, services, exceptions, support access, subprocessors, and backup locations.
Encryption and key management
Suivo uses encrypted network connections for supported production traffic. Cloud providers also encrypt managed storage at rest. For selected high-sensitivity content, including raw communication content and provider credentials, the application includes additional field-level envelope encryption using AES-256-GCM.
The reviewed production configuration requires Google Cloud Key Management Service for application envelope-key operations. Local development may use a separate local key mode and must not be represented as the production control.
Encryption reduces risk but does not replace access control, secure software, monitoring, or customer-side security. Information may necessarily be decrypted in memory when an authorized feature processes or displays it.
Identity and authentication
Suivo uses an external identity platform to authenticate users and may support email, Google, or Apple sign-in depending on the client and configuration. Suivo does not receive or store a user's Google, Apple, Gmail, or Microsoft account password. Connected accounts use scoped OAuth tokens or equivalent provider credentials.
Authentication tokens are validated by the API. Development-only header authentication is not intended for production. Customers should use strong authentication, enable multifactor authentication where available, protect recovery methods, and report lost devices or suspected account compromise promptly.
We may revoke sessions, connected-account credentials, device tokens, or access when we detect a security risk or when a user, customer administrator, or provider disconnects an account.
Authorization and tenant isolation
Suivo is designed to keep each customer team's records separate and to limit users to information they are authorized to access. The application uses layered authorization that includes authenticated user context, team scoping, roles, record ownership or assignment, explicit relationships, and PostgreSQL row-level security on protected data.
The operational roles reviewed in the application are Agent and Team Manager. A role does not, by itself, guarantee access to every record. Access may also depend on the record's authority, ownership, assignment, collaboration, underlying mailbox or conversation, and the user's current membership.
Delayed work—such as message synchronization, notification delivery, file scanning, AI processing, and voice finalization—is designed to carry bounded references rather than unrestricted user credentials and to re-evaluate authority before protected effects or disclosure. Revoked membership or stale work should fail closed.
No authorization design is self-proving. Suivo tests these boundaries and verifies production identities, but customers should still notify us immediately if they see information they believe is outside their authorized scope.
Database protections
Protected database tables use tenant identifiers, integrity constraints, purpose-specific functions, and row-level security. Security-sensitive tables are designed to use forced row-level security where required. Runtime database accounts are intended to be distinct from schema-owner or migration identities and to operate with least privilege.
Deployment controls validate important runtime identity and privilege expectations before protected work is accepted. These safeguards are designed to reduce the effect of an application defect; they are not a substitute for correct application authorization.
Connected email and calendar accounts
When a user connects Gmail, Google Calendar, Outlook, or Microsoft Calendar, Suivo requests provider scopes needed for the selected feature. The reviewed Gmail integration requests read-only mailbox access and message-send access. The reviewed Microsoft mailbox integration requests mailbox read/write, send, and basic user-profile permissions. Calendar access is enabled separately.
OAuth credentials are encrypted and access is limited to purpose-specific application paths. Users can disconnect connected services. Disconnecting stops future synchronization but may not delete synchronized business records. Gmail users have a separate Google-data deletion flow intended to revoke access and remove synchronized Gmail content, associated attachments, intake records, and derived Gmail workflow data. The Privacy Policy explains the distinction.
Remote images in email content are blocked by default in the supported viewers. A user must choose to load permitted remote images; invisible or suspicious tracking resources remain blocked. Email HTML is treated as untrusted, sanitized, and isolated from the surrounding application. Links may still lead to external sites, and users should evaluate them before opening.
AI-assisted processing
Suivo may use AI to classify inquiries, summarize communications, propose next actions, generate draft replies, title notes, transcribe dictation, and support voice conversations. Relevant customer content may therefore be sent to contracted AI or speech providers when the feature is invoked or enabled.
AI output can be inaccurate, incomplete, biased, or inappropriate. The application is designed to preserve human authority over important outbound communications and business decisions, but not every AI-derived internal classification or workflow update necessarily requires a separate click. Customers must review consequential output and must not treat it as legal, financial, tax, mortgage, appraisal, brokerage, fair-housing, or other professional advice.
We do not sell customer content or use it for third-party advertising. Provider use of submitted content is governed by the applicable provider contract, account settings, and enabled feature.
Voice, calls, recordings, and transcripts
When enabled, Suivo voice features may use telecommunications, speech recognition, text-to-speech, and AI providers. Audio is necessarily streamed through the systems required to conduct and transcribe a call. The application stores call metadata, events, transcripts, structured facts, and derived summaries. It also contains configurable paths for call recording and tightly scoped raw-audio or speech-to-text diagnostic capture.
Recording is not the same as transcription. A feature can transcribe live audio even when durable call recording is disabled. The service must therefore not claim that audio is never processed or that calls can never be recorded.
Customers are responsible for ensuring lawful calling, disclosure, consent, calling hours, do-not-call screening, and recording/transcription practices. Suivo's product controls do not replace those duties. Call recordings, raw-audio diagnostics, and full transcripts are treated as sensitive data and should be available only through purpose-bound access. Under Suivo's standard schedule, enabled call recordings are retained for 30 days, diagnostic raw-audio or speech-to-text samples for no more than 7 days, and transcripts under the owning Customer-record schedule, unless a shorter period, documented Customer instruction, or legal hold applies.
Files and attachments
Uploaded files are associated with an authorized parent record and stored under non-public object identifiers. Supported attachments enter a quarantine state and are not available for ordinary preview, download, or outbound use until the configured malware scanner returns a clean decision for the exact stored bytes.
The reviewed implementation uses a version-pinned ClamAV sidecar within Suivo-controlled infrastructure. Files that are pending, blocked, missing, inconsistent, or not successfully scanned remain unavailable. Malware scanning reduces risk but cannot guarantee that a file is harmless. Users should maintain endpoint protection and exercise care with downloaded or linked content.
Temporary signed download links are time-limited. Access to an attachment still depends on the current user's authority over its parent record.
Application, API, and network safeguards
The service includes controls designed to:
- validate authenticated requests and reject unapproved cross-origin browser calls;
- validate and normalize request bodies against explicit schemas;
- bound request sizes, transaction duration, provider calls, retries, queue work, and processing claims;
- keep external network calls out of protected database transactions;
- verify webhook signatures or shared secrets for supported providers;
- use idempotency and durable operation state to reduce duplicate messages, calls, and workflow effects;
- prevent stale workers from finalizing newer work;
- separate public failures from raw provider error details; and
- avoid putting message bodies, call transcripts, attachment bytes, credentials, or full provider identifiers into ordinary telemetry.
Some endpoints necessarily accept large bodies for supported uploads. Size limits are not a substitute for authentication, authorization, malware scanning, or storage controls.
Secrets and service identities
Production secrets are intended to be stored in managed secret systems and bound to narrowly scoped runtime identities. API, worker, deployment, migration, provider, storage, and key-management capabilities are separated by purpose where supported.
Secrets, OAuth tokens, API keys, raw email content, call audio, and provider payloads must not be included in support tickets or ordinary logs unless a specifically authorized, secure process requires them.
Logging, monitoring, and audit evidence
Suivo records operational and security telemetry needed to operate the service, investigate faults, enforce access, reconcile provider activity, and respond to incidents. Protected-content logs are designed to use bounded reason codes, pseudonymous correlation values, and aggregate metrics instead of message bodies, transcripts, attachment bytes, credentials, or arbitrary provider errors.
Certain business and security events are retained as audit or workflow evidence. Audit evidence is not an unrestricted administrator feed: viewing sensitive content should require the same underlying record authority or a separately approved exceptional-access process.
Ordinary authentication, security, and application logs are kept readily accessible for up to 90 days and in restricted archives for up to 12 months. Incident evidence may be retained for the applicable incident-register or legal-hold period. We do not promise that every user interaction is logged, or that logs are immutable forever.
Secure development and change management
The codebase uses typed request contracts, automated tests, database migration verification, dependency checks, static guards, authorization-denial tests, and deployment readiness checks. Security-sensitive changes are expected to preserve tenant isolation, least privilege, use-time authorization, revocation, bounded failures, and non-disclosure behavior.
Dependencies and container images are versioned or pinned where practical. Automated testing reduces risk but does not prove the absence of vulnerabilities. Production changes should be reviewed, traceable, reversible where feasible, and separated from schema-owner credentials.
Backups, resilience, and service availability
Suivo uses managed infrastructure and durable database records to reduce data loss and duplicate external effects. Queues and caches are treated as delivery accelerators rather than the sole authoritative record for critical accepted work.
Unless a signed agreement says otherwise:
- we do not promise uninterrupted or error-free service;
- no public uptime, recovery-time, or recovery-point objective is created by this page;
- backups may lag current activity and may not restore every transient state;
- deleting live data may not remove it instantly from encrypted, access-restricted backups, which are overwritten on Suivo's standard 35-day cycle; and
- restoration, disaster recovery, and provider continuity depend on third-party infrastructure as well as Suivo controls.
Incident response
Suivo maintains procedures intended to identify, contain, investigate, remediate, document, and learn from suspected security and privacy incidents. We will notify affected customers, individuals, regulators, or other parties when required by applicable law or a signed agreement. Notification timing and content depend on what is known, the risk of harm, legal restrictions, law-enforcement requests, and the customer's role in relation to the affected data.
Customers must promptly provide information and cooperation reasonably needed to investigate incidents involving their accounts, devices, users, integrations, or instructions.
Employee, contractor, and support access
Suivo personnel and contractors should access customer information only when needed to provide support, maintain security, comply with law, or perform another authorized business purpose. Access should be limited by role and logged where appropriate.
Google Workspace data is subject to additional Limited Use restrictions. Human access to that data is prohibited except with the user's affirmative agreement to view specific data, when necessary for security, when required by law, or when appropriately aggregated for internal operations as permitted by Google's policy.
Suivo does not promise that no human can ever access customer data. A truthful security program must preserve narrow, auditable access for legitimate support, security, and legal needs.
Independent assurance and certifications
As of the date of this page, do not assume that Suivo has SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, CyberSecure Canada, or any other certification or independent attestation unless we provide a current report or certificate that expressly covers the service and period in question.
We do not publish penetration-test details, architectural secrets, credentials, exploit information, or customer-specific security evidence on this page. Customers with a legitimate need may request available security documentation, subject to confidentiality and verification.
Responsible security reporting
If you believe you have found a security vulnerability, email <contact@suivo.ca> with:
- a clear description of the issue and its potential impact;
- the affected URL, application version, or feature;
- reproducible steps, with screenshots or a minimal proof of concept where safe;
- the time and time zone of relevant activity; and
- a way to contact you securely.
Please do not:
- access, modify, download, retain, or disclose another person's or customer's data;
- use social engineering, phishing, physical intrusion, denial of service, spam, malware, destructive testing, automated high-volume scanning, or attacks on third-party providers;
- test against production records beyond the minimum needed to demonstrate the issue safely;
- violate law, privacy rights, or third-party terms; or
- publicly disclose a suspected vulnerability before Suivo has had a reasonable opportunity to investigate and remediate it.
We will acknowledge good-faith reports as reasonably practicable. Unless a separate written program says otherwise, this page does not create a bug bounty, promise payment, authorize unlawful conduct, waive rights, or provide a legal safe harbour.
Security questions
For security questions, incident reports, or requests for available security documentation:
Suivo Technologies Inc.
Federal corporation number: 1001698079
Québec enterprise number (NEQ): Pending
Security contact: <contact@suivo.ca>
Website: https://suivo.ca
For privacy rights or complaints, use the privacy contact listed in the Privacy Policy.
Changes to this page
We may update this page as the service, providers, or safeguards change. A change to this page does not reduce a security commitment in a signed agreement unless that agreement permits the change. Material changes to personal-information practices will be handled under the Privacy Policy and applicable law.