Data & Trust

Your Relationships, Protected

Via AI is built on a consent-first data model. We access only what you explicitly authorize — email headers, not bodies; connection lists, not profile data. We store only what's needed to build your relationship graph. Your graph is never shared with other customers, never sold to third parties, and never used to populate anyone else's paths.

The Permissions Model

What Via AI sees — and what we don't

Diagram showing Via AI permissions model — what data is accessed versus what is stored

What Via AI reads

  • Email header metadata: To, From, CC — not email body content
  • LinkedIn connection lists — names and current roles of 1st-degree connections
  • CRM contact and account records you choose to sync
  • Calendar event participant lists (optional, for relationship weighting)

What Via AI never does

  • We do not read, store, or process email body content
  • We do not scrape public web pages or LinkedIn profiles
  • We do not share your relationship graph with other customers
  • We do not sell contact data to third parties
  • We do not access data sources you haven't explicitly authorized

What we've built — and what we're building toward

We handle contact metadata and relationship data. Here's how it's secured at every layer — and an honest note on where we are in our compliance roadmap.

Encryption at rest

All relationship graph data and contact metadata is encrypted at rest using AES-256. Database encryption keys are rotated on a 90-day cycle and stored separately from the data they protect.

Encryption in transit

All data in transit between your browser, our API, and third-party integrations is encrypted using TLS 1.3. We enforce HSTS and reject HTTP connections. OAuth tokens are never transmitted in URL parameters.

Access controls

Via AI uses per-user OAuth scopes for all third-party integrations. Only the scopes required for the feature are requested. Internal access to production data is logged, requires MFA, and follows least-privilege principles.

Isolated org graphs

Each organization's relationship graph is stored in a logically isolated data partition. One customer's graph is never used to populate or train another customer's graph. Org isolation is enforced at the API layer, not just the database layer.

Building toward SOC 2

We are building toward SOC 2 Type II certification and have designed our systems and access controls with that framework in mind. We are not yet SOC 2 certified. Enterprise customers with compliance requirements are welcome to contact us to discuss our roadmap.

Data deletion on request

Any user can request full deletion of their relationship graph and connected data at any time. We process deletion requests within 30 days. CRM sync records are also purged. Email us at [email protected] to request deletion.