Skip to content

Security

Your AI data stays under your control

See what Block Convey collects, how it moves, who can access it, and which controls apply to your setup.

Data flow

Know where the data goes

Every deployment follows the same path. The parts you own stay yours.

  1. 01User or applicationCustomer
  2. 02AI workflowCustomer
  3. 03PRISM connection pathShared
  4. 04PRISM processing and storageBlock Convey
  5. 05Dashboard, findings, and reportsBlock Convey

What is collected

Only what the product needs to explain a failure

The exact fields depend on the integration and your configuration. Each integration guide states what that path sends.

  • Prompts and responses when configured
  • Session and trace identifiers
  • Model and provider metadata
  • Tool calls and results when supplied
  • Retrieval context when supplied
  • Timing, token, cost, and error data when supplied
  • Evaluation, Guardrail, and remediation results
  • User identifiers only as configured by the customer

Controls

What your security review will ask about

Each of these is confirmed for your specific connection path during setup rather than claimed generically here.

  • PII and sensitive data

    Which checks are supported on your path, whether redaction runs before storage, and what evidence is retained.

  • Access and credentials

    Project-scoped credentials, API key handling, roles and permissions, tenant isolation, audit history, and rotation.

  • Storage and retention

    Hosting regions, default retention by plan, deletion process, backups, and export options.

  • Deployment options

    Hosted by default. Private deployment, dedicated infrastructure, and data residency are contract-scoped Enterprise options.

Have a security question before connecting?

Tell us your connection path and we will confirm exactly what it sends.