Security
Last updated: September 14, 2026
A plain-language summary of how Vira handles and protects data. For the legal terms governing data processing, see our Privacy Policy. If you need something here documented in more depth for a vendor-security review, contact us — see Clause 18 of the Privacy Policy.
Encryption in transit
Yesvira.chat is served over HTTPS/TLS. Data moving between your browser or app and our servers is encrypted in transit.
Encryption at rest
PartialStaff mailbox credentials (SMTP/IMAP passwords for the "My Email" feature) are encrypted at rest with AES-256-GCM before being stored. Broader database-level or disk-level encryption at rest is not yet applied to the rest of the database (messages, CRM records, other stored credentials) at the application layer.
Database provider
YesSelf-hosted MySQL/MariaDB — not a third-party managed database service.
Cloud / hosting provider
YesNamecheap (shared/VPS hosting).
Data residency
PendingThe specific server region for our Namecheap hosting plan is not yet confirmed on this page — contact us for the current answer.
Backup policy
Not yetNo automated backup schedule is currently documented. Contact us for our current backup arrangements.
Retention period
YesAccount data is retained while your account is active, and up to 12 months after closure. Message content is retained while it remains in your chat history, or until deleted — see Privacy Policy Clause 8 for the full terms.
Data deletion procedure
PartialYou can delete individual messages and edit your profile directly in the app. A full account/data erasure request is handled by contacting us (Privacy Policy Clause 12) rather than as a fully automated self-service flow today.
Subprocessors
YesCurrent subprocessors, each limited to what its function requires:
- OpenAI — only for organizations that enable the optional AI Reply feature
- Expo — delivering mobile app push notifications
- Google Analytics (GA4) — website usage analytics
- Your own browser/device's push service (e.g. Chrome/Firefox) — delivering web notifications
AI-model data handling
YesAI Reply is off by default and only processes conversation text for organizations that turn it on, sending that text to OpenAI's API to generate a suggested reply a staff member reviews before sending.
Are conversations used to train AI models?
Not yetNo. Under OpenAI's standard API terms, data submitted through its API is not used to train its models by default.
Employee access controls
PartialWithin the product: role-based access control (Admin/Supervisor/Agent, plus granular permissions) — staff only see what their role and department grant them. Fansoft's own internal access controls over production systems are not yet published here in detail — contact us for that documentation.
Audit logs
YesAdministrative actions are recorded in an audit log.
Two-factor authentication (2FA)
Not yetNot currently available. Accounts sign in with phone number and password.
Single sign-on (SSO)
Not yetNot currently available.
SOC 2
Not yetNot currently certified.
ISO 27001
PendingCertification status is being confirmed — contact us for current documentation before relying on this for a vendor review.
GDPR / DPA documentation
PartialOur Privacy Policy is written for compliance with Kenya's Data Protection Act, 2019 — see below. A separate GDPR-specific data processing addendum is not yet published; contact us if you need one.
Kenya Data Protection Act compliance
YesOur Privacy Policy is issued in compliance with the Data Protection Act, 2019 (Laws of Kenya).
Breach notification procedure
YesIn the event of a breach likely to risk your rights and freedoms, we notify the Office of the Data Protection Commissioner within the Data Protection Act's required timelines (generally within 72 hours of becoming aware) and notify affected users without undue delay where required by law — see Privacy Policy Clause 15.
