Skip to content

Trust & security

Understand the controls before you connect your work.

See what’s available, how actions are reviewed, and what must be verified before live use. A useful evaluation starts with clear expectations.

Availability

Start with a guided evaluation

Covinly is accepting requests for guided early-access evaluations. Bring the work you want to automate across your tools. We review your process, permissions, and human review points together, then agree a supported scope.

Requesting access starts that conversation; it does not create an account or promise a live connection. Published examples use sample data and do not establish customer results.

Current product scope

Early access covers reviewed automations, forms, booking pages, and the workspace’s approval, activity, and usage views. We confirm the supported actions and connections for your process during evaluation.

Voice is currently limited to recorded rehearsals; live calling is not available. Open-ended creation from a prompt is not available as a self-service feature.

Permissions & review

Permissions are set before work begins

Each workflow has a fixed set of allowed actions. Incoming content can affect a decision, such as whether a lead qualifies, but it cannot grant new permissions or change values locked when the workflow was published.

What an approval controls

In a lead follow-up workflow, CRM contact creation and a message to a fixed Slack channel happen automatically. The email to the lead pauses for review. A reviewer can inspect and edit the allowed fields, approve the reply, or decline it.

A decline stops the run without sending that email; it does not undo earlier steps. Review points apply to the actions defined in that workflow.

Data & records

Model data terms must be verified before live use

Our production policy requires zero-data-retention and no-training terms for model processing. The system rejects providers that are not configured as covered by those terms.

Provider agreements and account settings must also be verified before customer data is used. A configuration check alone does not establish a contract, and this page does not confirm that those external arrangements are complete.

Recorded outcomes and verified outcomes are distinct

Each run keeps an append-only event log, including the outcome that action was recorded as. The detailed history is available for inspection; nothing is summarized away. Independent checks are stored separately where supported.

Today those checks run against Covinly’s own records; verification against outside accounts still depends on their connections. The weekly summary states how much work can be confirmed and never rounds that figure up.

Workspace data has defined deletion boundaries

Data access is scoped to a workspace. Workspace deletion removes operational data across the stores covered by the deletion process. Audit and billing evidence are retained; deletion does not mean every record disappears.

We review the applicable retention and deletion scope with you before a live pilot.

Readiness

Readiness and external reviews

SOC 2 readiness, Google restricted-scope verification, and publication of the subprocessor list remain incomplete. Current production deployment and live customer results have not been verified for this page.

We will confirm supported connections, provider terms, and readiness with you before agreeing to live use.

To discuss a workflow and the controls it needs, request early access.

Security questions or vulnerability reports: access@covinly.com. There is no separate disclosure inbox and no published security.txt yet.

Last reviewed against the source code on .