Enterprise-grade security for your restaurant data
Last Updated: March 2, 2026
At Nirvah AI, security isn't an afterthought—it's foundational to everything we build. We understand that you're trusting us with your business data, and we take that responsibility seriously.
Nirvah AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. See our Privacy Policy for full details.
All sensitive credentials (OAuth tokens, webhook secrets) and customer PII (phone numbers, names, email addresses, delivery addresses) are encrypted using AES-256-GCM at the application level before storage. Encryption keys are managed through secure environment variables and never stored in the database.
All data transmitted between your browser and our servers is protected using TLS 1.2 or higher encryption protocols.
Nirvah AI employs strict logical separation of customer data. Restaurant data from Google Business Profile, Square POS, and KitchenHub is isolated at the database level using Row Level Security (RLS). Cross-tenant data access is architecturally impossible.
SOC2 Readiness: Our infrastructure and practices are designed to meet SOC2 Type II requirements. We are actively working toward formal certification.
Google Data Deletion: Google Business Profile review data is immediately purged from all systems when the integration is disconnected, in compliance with the Google API Services User Data Policy.
We implement multiple layers of access control to protect your account:
We enforce strict boundaries on how customer data is processed by AI systems:
We carefully vet all third-party vendors and require them to meet our security standards:
| Vendor | Purpose | Compliance |
|---|---|---|
| Supabase | Database & Auth | SOC2 Type II |
| Vercel | Hosting & Edge | SOC2 Type II |
| OpenAI / Anthropic | AI Inference & Receipt OCR (Vision) | SOC2 Type II |
| LiveKit | Voice AI Infrastructure | SOC2 Type II |
| Deepgram | Speech-to-Text | SOC2 Type II |
| Cartesia | Text-to-Speech | SOC2 Type II |
| Stripe | Payments | PCI DSS Level 1 |
| Google Cloud Platform | API Infrastructure & Business Profile | SOC2 Type II, ISO 27001 |
| Square | POS Data Integration | PCI DSS Level 1, ISO 27001 |
| KitchenHub | POS Middleware (Toast & Clover) | Enterprise Security |
| Twilio | SMS & Voice Telephony | ISO 27001 |
We maintain a comprehensive incident response plan to quickly address any security events:
We design our systems to meet or exceed industry compliance requirements:
Data protection rights for EU residents
Privacy rights for California residents
Security, availability, and confidentiality
Telephone consumer protection
We retain data only as long as necessary for the services we provide. Below are our standard retention periods:
| Data Type | Retention Period |
|---|---|
| Call recordings | 90 days |
| Call transcripts | 1 year |
| Order data | 2 years |
| Google Business Profile data | Until integration disconnect or account deletion. All synced review data is immediately deleted upon disconnection. |
| Restaurant leads | Until deleted by user |
| Log data | 30 days |
If you discover a security vulnerability or have security-related questions, please contact us immediately:
We take all security reports seriously and will respond within 24 hours.