1. Introduction and Scope
This Security Overview ("Security Description") is incorporated into, and forms part of, the Grovity Terms and Conditions accepted by the Client, or any signed master sales agreement or other similar written agreement between Grovity and the Client (collectively, the "Agreement"). References to "Grovity" in this document refer to Grovity Services LLC, [REGISTERED ADDRESS], United States, and its affiliates. "Customer" or "Client" refers to the contracting Customer and its affiliates.
The purpose of this Security Description is to describe the security program applicable to the Grovity Services ("Services") and the minimum security standards that Grovity maintains to protect Customer Data (as defined in the Agreement) from unauthorized use, access, disclosure, theft, or manipulation. As security threats evolve, Grovity continues to update its security program and strategy. Grovity reserves the right to update this Security Description from time to time; any update will not materially reduce the general protections set forth herein. Any capitalized term not defined here will have the meaning given in the Privacy Agreement.
2. Compliance and Frameworks
Grovity's security program is aligned with widely recognized industry standards and frameworks, including:
SOC 2 Type II principles for security, availability, confidentiality, and processing integrity.
ISO/IEC 27001 Information Security Management System framework.
NIST SP 800-53 and NIST SP 800-61 for security controls and incident response.
AWS Well-Architected Framework, with the security pillar applied to platform design.
Compliance with applicable data protection laws, including the GDPR, the CCPA/CPRA, Colombian Law 1581 of 2012 and Decree 1377 of 2013, and the Brazilian LGPD.
Alignment with platform-partner requirements, including Meta Business Platform security expectations and the requirements of integrated payment networks.
Grovity inherits and complements the compliance certifications of its critical cloud and AI providers (which themselves maintain SOC 2 Type II, ISO 27001, GDPR, CCPA, and equivalent certifications). Independent third-party audits are conducted on the providers; Grovity's own controls are reviewed by internal audit and external assessors as part of its continuous-improvement cycle.
3. Covered Services and Exclusions
This Security Description applies to the architectural, administrative, technical, and physical controls that Grovity implements for the production Services. The following are not covered:
Beta or Alpha offerings (as described in the Terms and Conditions).
Services provided directly by telecommunications carriers, third-party AI providers, or other independent third parties, which are governed by the security descriptions of those providers.
Customer-controlled environments, including the Customer's devices, networks, integrations developed by the Customer, and any system outside Grovity's reasonable control.
4. Organization and Security Program
Grovity maintains a risk-based information-security program covering administrative, technical, and physical safeguards. The program is appropriate to the nature of the Services, the size and complexity of Grovity's operations, and the sensitivity of the data processed. The security program covers, at a minimum:
Policies and Procedures
Asset Management
Access Management and Identity
Cryptography and Key Management
Physical and Environmental Security (provided through certified cloud regions)
Operations Security
Communications Security
Business Continuity and Disaster Recovery
Human Resources Security
Product and Application Security
Cloud and Network Infrastructure Security
Vulnerability and Patch Management
Third-Party / Vendor Security
Security Monitoring and Incident Response
Compliance and Internal Audit
Information security policies and standards are reviewed and approved at least annually and are made available to Grovity employees. Security is sponsored at the executive level and reported to the founders and senior leadership on an ongoing basis.
5. Confidentiality
Grovity has controls in place to maintain the confidentiality of the Customer Data made available to the Services in accordance with the Agreement. All Grovity employees and contracted personnel are bound by internal policies and signed agreements obligating them to maintain confidentiality of Customer Data. Periodic compliance reviews are conducted on personnel and vendor procedures.
6. People Security
6.1. Background Verification
Grovity conducts background checks on individuals who join Grovity in accordance with applicable local laws. Verifications typically include education, previous employment, and reference checks. Where permitted by local law and depending on the role, additional checks (such as criminal, credit, or sanctions checks) may be performed.
6.2. Security and Privacy Training
All employees must complete security and privacy training at least annually, covering security policies, secure-development practices, social-engineering awareness, and privacy principles. Grovity also conducts periodic phishing-awareness exercises and communicates emerging threats to its workforce. An ethics and security reporting channel is available for employees.
7. Third-Party / Vendor Management
7.1. Vendor Assessment
Grovity may use third-party providers (such as cloud infrastructure providers, AI model providers, messaging providers, payment processors, and other integration partners) to deliver the Services. Grovity performs a risk-based security assessment of prospective vendors before engagement, and reviews each vendor periodically against business-continuity, security, and data-protection standards. Customer Data is required to be returned and/or deleted at the end of the relationship with a vendor.
For clarity, telecommunications carriers and payment networks are not considered subprocessors of Grovity; their services are governed by their own terms.
7.2. Vendor Agreements
Grovity enters into written agreements with its vendors that include confidentiality, privacy, security, and data-protection obligations consistent with applicable law. Vendors are subject to ongoing oversight and at least annual evaluations.
8. Architecture and Data Segregation
The Grovity platform is hosted on enterprise-grade public cloud infrastructure, operated by a leading hyperscale cloud provider, with deployments primarily in the United States (and, where required, in additional regions configured for specific Customers). The platform is implemented as a multi-tenant, cloud-native architecture, defined as Infrastructure-as-Code to ensure reproducibility, auditable change management, automatic scalability, and the elimination of single points of failure.
The production environment is deployed in logically isolated virtual private cloud (VPC) environments dedicated to Grovity. Strict per-tenant isolation is enforced at the application layer: every record processed by the Services is bound to a tenant identifier, and every query is filtered by that identifier. It is architecturally impossible for one tenant to access another tenant's data through normal Service operations.
The infrastructure spans multiple fault-independent availability zones in physically separated geographic locations within the chosen cloud region, providing redundancy and high availability for the Services.
9. Access Controls
9.1. Access Provisioning
Grovity follows the principle of least privilege through a role-based access control (RBAC) model when provisioning access to internal systems. Personnel are authorized to access Customer Data only based on their job function, role, and responsibilities, and such access requires approval from the responsible manager. Access rights to production environments are reviewed at least semi-annually. Access is revoked promptly upon termination of employment.
To access the production environment, authorized users must use unique credentials with multi-factor authentication (MFA) and connect through approved corporate channels (such as a corporate VPN or equivalent secure access). High-risk actions and configuration changes in production are logged. Grovity uses automation to detect deviations from internal technical standards that could indicate anomalous or unauthorized activity.
9.2. Password and Authentication Controls
Grovity's password policy follows NIST SP 800-63B guidance, emphasizing longer passwords combined with multi-factor authentication rather than overly restrictive complexity rules. Customer credentials are stored using strong one-way hashing. Customers may enable two-factor authentication (2FA / MFA) for their own users and may federate authentication with their corporate Identity Provider (IdP) through OIDC or SAML 2.0.
10. Change Management
Grovity has a formal change management process to manage changes to software, applications, and system configurations deployed to production. Change requests are documented in an auditable system of record. Before any high-risk change is deployed, an impact and risk assessment is performed, including approval by the appropriate decision-makers, testing, and rollback procedures. Changes are reviewed and tested prior to production deployment.
11. Encryption
11.1. Encryption in Transit
All public communication channels of the platform are encrypted using TLS 1.2 or higher, with TLS 1.3 preferred. Older protocols (TLS 1.1, TLS 1.0, and SSLv3) are disabled. Modern cipher suites with Perfect Forward Secrecy (PFS) and Authenticated Encryption with Associated Data (AEAD) are used (such as TLS_AES_128_GCM_SHA256, TLS_AES_256_GCM_SHA384, and ECDHE-RSA-AES256-GCM-SHA384). Weak ciphers (RC4, 3DES, MD5, EXPORT-grade) are explicitly disallowed. Certificate validation is enforced on all peer connections.
11.2. Encryption at Rest
Customer Data at rest is encrypted using AES-256 managed by the underlying cloud provider's key management service (KMS), or equivalent service-specific encryption. The most sensitive data (such as third-party credentials, API tokens, and cryptographic keys for partner integrations) receives an additional application-level encryption layer.
11.3. Key Management
Grovity uses the cloud provider's key management service to manage symmetric keys with automatic rotation enabled. Customer-Managed Keys (CMK) or Bring-Your-Own-Key (BYOK) options are available for enterprise Clients with specific requirements, subject to a separate commercial agreement. Access to keys and secrets is logged and limited to authorized personnel.
12. Certificates
Grovity uses TLS certificates issued by reputable certificate authorities, with automatic renewal and Certificate Transparency enabled. Grovity supports both RSA and ECDSA certificates depending on the specific deployment and Client requirement.
13. Web Application Firewall and DDoS Protection
A Web Application Firewall (WAF) inspects requests to public endpoints, blocking or challenging traffic that matches known attack patterns (such as those identified by the OWASP Top 10). Distributed Denial-of-Service (DDoS) protection is provided by the cloud provider's standard mitigation services, supplemented by Grovity's internal rate-limiting controls.
14. Vulnerability Management
Grovity maintains controls and policies to mitigate the risk of security vulnerabilities within a measurable timeframe that balances risk and operational requirements. Vulnerability scans are performed regularly using industry-standard tools against the cloud infrastructure and corporate systems. Critical patches are evaluated, tested, and deployed proactively. For Grovity Services, operating-system patches are applied through rebuild-and-deploy cycles of the base images.
15. Penetration Testing
Grovity engages independent third parties to perform periodic application-level penetration testing. Findings are prioritized, triaged, and remediated by Grovity's security team in accordance with internal SLAs based on severity. A summary report from the most recent assessment may be provided under NDA upon Client request.
16. Security Incident Management
Grovity maintains incident-management policies and procedures aligned with NIST SP 800-61. The Security Incident Response Team assesses the threat of all relevant vulnerabilities and security incidents and establishes containment, remediation, and post-incident actions. Security logs are retained for a defined period sufficient for forensic analysis and applicable regulatory requirements, and access is limited to authorized personnel.
Upon discovery or notification of a security incident, Grovity will:
Promptly investigate the incident.
To the extent permitted by applicable law, notify the affected Client without undue delay and, in any case, within seventy-two (72) hours after becoming reasonably aware of an incident that affects or may affect Customer Data.
Take necessary corrective measures to resolve the incident.
Cooperate with the Client in handling regulatory notifications and data-subject communications, to the extent the incident falls within Grovity's reasonable control.
17. Resilience and Continuity of Service
Grovity's infrastructure uses multiple tools and mechanisms to achieve high availability and resilience. The infrastructure spans multiple fault-independent availability zones in physically separated locations. Manual and automatic capabilities are available to redirect and regenerate hosts within the infrastructure. Monitoring tools detect host or zone issues in real time, and orchestration tools rebuild hosts from the latest healthy state when needed.
Specialized tools continuously monitor server performance, data, and traffic load. If suboptimal performance or overload is detected, traffic is shifted or capacity is increased to maintain the Service. Multi-level alerting allows the operations team to take immediate corrective action when automated mechanisms are not sufficient.
17.1. Recovery Objectives
Recovery Time Objective (RTO): < 1 hour for critical incidents, supported by a serverless architecture that recovers automatically without manual intervention.
Recovery Point Objective (RPO): < 15 minutes, supported by continuous replication and point-in-time recovery for the primary data stores.
18. Backup and Recovery
Grovity regularly backs up critical data (account information, logs, conversation history, files, and other operational data) using the cloud provider's managed storage. Backups are preserved redundantly across availability zones and are encrypted in transit and at rest using AES-256 server-side encryption. Backup retention follows defined retention cycles aligned with regulatory requirements and the limitations described in the Terms and Conditions.
19. Data Residency and International Transfers
Grovity's production infrastructure is hosted primarily in cloud regions located in the United States. International transfers of personal data are governed by the Privacy Agreement and the applicable contractual mechanisms (such as Standard Contractual Clauses for GDPR transfers, the contractual mechanisms required by Colombian Law 1581/2012, and the international transfer rules of the LGPD). If a specific Client requires deployment in an additional region, the Infrastructure-as-Code architecture allows Grovity to replicate the production stack in alternative cloud regions, subject to a separate commercial agreement.
20. Logging and Observability
Grovity maintains centralized logging, application performance monitoring, and error tracking. Sensitive data (such as credentials, tokens, full payment information, and message contents) is redacted before being written to operational logs. Logs are accessible only to authorized personnel and are retained for periods aligned with regulatory and contractual requirements.
21. Client Responsibilities
The Client is responsible for: (i) keeping its credentials and authentication factors secure; (ii) properly configuring its tenant, including access roles and integration credentials; (iii) ensuring its End Users comply with the Acceptable Use Policy; (iv) classifying the data it submits and avoiding the transmission of categories of data that exceed the scope of the contracted Service; and (v) implementing complementary controls (such as data classification, retention policies, and access reviews) on its own environment.
22. Updates
Grovity reserves the right to update this Security Description from time to time. Updates will not materially reduce the general protections set forth in this document. Material changes will be communicated in accordance with the Terms and Conditions.
Grovity Services LLC
[REGISTERED ADDRESS]
info@grovity.ai | https://www.grovity.ai