Back to Vira

Security

Last updated: September 14, 2026

A plain-language summary of how Vira handles and protects data. For the legal terms governing data processing, see our Privacy Policy. If you need something here documented in more depth for a vendor-security review, contact us — see Clause 18 of the Privacy Policy.

Encryption in transit

Yes

vira.chat is served over HTTPS/TLS. Data moving between your browser or app and our servers is encrypted in transit.

Encryption at rest

Partial

Staff mailbox credentials (SMTP/IMAP passwords for the "My Email" feature) are encrypted at rest with AES-256-GCM before being stored. Broader database-level or disk-level encryption at rest is not yet applied to the rest of the database (messages, CRM records, other stored credentials) at the application layer.

Database provider

Yes

Self-hosted MySQL/MariaDB — not a third-party managed database service.

Cloud / hosting provider

Yes

Namecheap (shared/VPS hosting).

Data residency

Pending

The specific server region for our Namecheap hosting plan is not yet confirmed on this page — contact us for the current answer.

Backup policy

Not yet

No automated backup schedule is currently documented. Contact us for our current backup arrangements.

Retention period

Yes

Account data is retained while your account is active, and up to 12 months after closure. Message content is retained while it remains in your chat history, or until deleted — see Privacy Policy Clause 8 for the full terms.

Data deletion procedure

Partial

You can delete individual messages and edit your profile directly in the app. A full account/data erasure request is handled by contacting us (Privacy Policy Clause 12) rather than as a fully automated self-service flow today.

Subprocessors

Yes

Current subprocessors, each limited to what its function requires:

  • OpenAI — only for organizations that enable the optional AI Reply feature
  • Expo — delivering mobile app push notifications
  • Google Analytics (GA4) — website usage analytics
  • Your own browser/device's push service (e.g. Chrome/Firefox) — delivering web notifications

AI-model data handling

Yes

AI Reply is off by default and only processes conversation text for organizations that turn it on, sending that text to OpenAI's API to generate a suggested reply a staff member reviews before sending.

Are conversations used to train AI models?

Not yet

No. Under OpenAI's standard API terms, data submitted through its API is not used to train its models by default.

Employee access controls

Partial

Within the product: role-based access control (Admin/Supervisor/Agent, plus granular permissions) — staff only see what their role and department grant them. Fansoft's own internal access controls over production systems are not yet published here in detail — contact us for that documentation.

Audit logs

Yes

Administrative actions are recorded in an audit log.

Two-factor authentication (2FA)

Not yet

Not currently available. Accounts sign in with phone number and password.

Single sign-on (SSO)

Not yet

Not currently available.

SOC 2

Not yet

Not currently certified.

ISO 27001

Pending

Certification status is being confirmed — contact us for current documentation before relying on this for a vendor review.

GDPR / DPA documentation

Partial

Our Privacy Policy is written for compliance with Kenya's Data Protection Act, 2019 — see below. A separate GDPR-specific data processing addendum is not yet published; contact us if you need one.

Kenya Data Protection Act compliance

Yes

Our Privacy Policy is issued in compliance with the Data Protection Act, 2019 (Laws of Kenya).

Breach notification procedure

Yes

In the event of a breach likely to risk your rights and freedoms, we notify the Office of the Data Protection Commissioner within the Data Protection Act's required timelines (generally within 72 hours of becoming aware) and notify affected users without undue delay where required by law — see Privacy Policy Clause 15.