Security
Your AI data stays under your control
See what Block Convey collects, how it moves, who can access it, and which controls apply to your setup.
Data flow
Know where the data goes
Every deployment follows the same path. The parts you own stay yours.
- 01User or applicationCustomer
- 02AI workflowCustomer
- 03PRISM connection pathShared
- 04PRISM processing and storageBlock Convey
- 05Dashboard, findings, and reportsBlock Convey
What is collected
Only what the product needs to explain a failure
The exact fields depend on the integration and your configuration. Each integration guide states what that path sends.
- Prompts and responses when configured
- Session and trace identifiers
- Model and provider metadata
- Tool calls and results when supplied
- Retrieval context when supplied
- Timing, token, cost, and error data when supplied
- Evaluation, Guardrail, and remediation results
- User identifiers only as configured by the customer
Controls
What your security review will ask about
Each of these is confirmed for your specific connection path during setup rather than claimed generically here.
PII and sensitive data
Which checks are supported on your path, whether redaction runs before storage, and what evidence is retained.
Access and credentials
Project-scoped credentials, API key handling, roles and permissions, tenant isolation, audit history, and rotation.
Storage and retention
Hosting regions, default retention by plan, deletion process, backups, and export options.
Deployment options
Hosted by default. Private deployment, dedicated infrastructure, and data residency are contract-scoped Enterprise options.
Disclosures
Documents and contacts
Have a security question before connecting?
Tell us your connection path and we will confirm exactly what it sends.