convalesce
/securitySecurity and data

What Convalesce reads, sends and changes.

Convalesce works on your pipelines, so this page says plainly what it touches. Where an answer rests on the legal pages, it links to the part it comes from.

What Convalesce reads

The shape of your data, all the time: schemas, types, row counts and lineage.

While it investigates a failure it may also run small read-only queries to confirm a cause. Those are capped, personal columns are masked, and the rows are never stored.

From the DPA, section 6.1.

What leaves your environment

Only the incident bundle for the failed run, and only what the investigation needs. It is not a copy of your warehouse.

Before that context goes to the AI model, Convalesce masks personal information inside its own cloud environment. Automated masking cannot be guaranteed to catch every item, so it reduces that exposure and does not remove it.

Convalesce does not use customer personal data to train general AI models, and does not instruct its AI provider to.

From the DPA, section 6.2 and DPA, section 6.3.

What it can change

Nothing on its own. The most it does is open a pull request against your repository, with the evidence attached. You review it and you merge it.

The access you choose

Reading is set per connection, and you can switch it off for any of them.

Access to your code is a separate step: you install the GitHub app on the repositories you pick.

You can revoke a connected integration. Once it is revoked, Convalesce stops making new requests with it.

From the DPA, schedule 2.

The measures in place

Encryption
Information is encrypted in transit.
Sign-in
Multi-factor authentication for internal and administrative access.
Access
Role-based access controls, least-privilege service accounts, and restrictions on staff access to customer data.
Secrets
Integration credentials and secrets are kept in Google Secret Manager.
Environments
Development and production are kept separate.
Logging
Audit logging for the operation and security of the service.
Hosting
Google Cloud, region us-central1 (Iowa, United States).
Deletion
Customer data is deleted within 60 days of a valid deletion request or the end of an account, with the limited exceptions the DPA sets out.
Incidents
You are told without undue delay once a security incident affecting your personal data is confirmed.

From the DPA, schedule 2, with section 11 and section 15.

Who else processes your data

Convalesce does not sell or rent customer personal data, and does not use it for advertising.

The providers that process data on its behalf are listed in the data processing addendum, and a change to that list comes with notice. The privacy policy covers the personal data Convalesce holds about its own users, and the terms of service cover your use of the product.

A question about any of this goes to privacy@convalesce.io.