Amazon Web Services
S3 object storage
Holds every file a workspace keeps: uploads, email and chat attachments, knowledge sources, call recordings and voicemail, and profile photos.
A small number of companies help us run Plexvia. This page names every one of them, what we use it for, and the data it receives.
A subprocessor is a company we ask to do part of the work: keeping a file safe, carrying a call, taking a payment. Some of your data reaches them so that Plexvia can do its job, which means you should be able to see who they are without having to ask.
This is that list. It covers the product and this website, it lives in version control beside the code that calls each provider, and it changes only in a reviewed commit.
Every provider appears with the service we use and the data it receives. No page on this site says “various cloud vendors”.
A provider is sent what its part of the work needs. The carrier that connects a call is not given your knowledge base.
Where a provider processes data is published once a person has confirmed it. Until then this page says so plainly.
Where Plexvia runs, and where a workspace’s data rests between one action and the next.
S3 object storage
Holds every file a workspace keeps: uploads, email and chat attachments, knowledge sources, call recordings and voicemail, and profile photos.
KMS key management
Wraps and unwraps the encryption key belonging to each workspace, so stored conversations can only be opened with a key we have to ask for.
KMS never receives message content. It handles keys, and nothing that a key protects.
Malware scanning, on Lambda with ClamAV
Reads the full contents of every uploaded and crawled file before anything else in Plexvia is allowed to open it or link to it.
This is the heaviest single disclosure in the product, and the one most often left off a list like this. It is here because the scanner sees whole files.
PostgreSQL and Redis
Holds the working record of a workspace: messages, customer records, call transcripts, search indexes, and the jobs waiting their turn.
We will name the provider here once we have read it from that provider’s own records. Our configuration is not evidence of it.
The model provider behind every answer, summary and suggestion Plexvia writes.
Language, embedding and voice models
Drafts and suggests replies, summarises conversations, makes knowledge and transcripts searchable by meaning, and speaks on a call the AI answers.
This is the widest flow of content in Plexvia, so it is the entry to read first. A model is called when a feature that needs one is used, not on everything a workspace holds.
The carriers that move a message the last step, from Plexvia to a phone, an inbox or a device.
Voice carrier
Carries calls to and from a Plexvia number, and holds the number itself.
Used only by workspaces using Plexvia Voice, which is not yet generally available. The carrier’s own copy of a recording is deleted once ours is stored.
Transactional email
Delivers the mail Plexvia sends on its own behalf: address verification, password resets, workspace invitations and notifications.
A workspace’s mail to its own customers goes out through the mailbox that workspace connected, and never passes through Resend.
SNS text messaging
Sends the one time code that confirms a user’s own mobile number.
Browser push endpoints
Delivers a notification to a browser that asked to receive them.
The receiving service is chosen by the visitor’s browser, not by Plexvia, and the contents are encrypted to that device before they leave us.
Confirming that the person a business names as responsible for a regulated phone line is who they say they are.
Plaid Identity Verification
Confirms the identity of the person a business names as responsible for its phone service before a line is activated, and, where the check includes it, screens that person against sanctions and politically exposed person lists.
The document, the photograph and the date of birth are given to Plaid directly, inside its own flow, and never pass through Plexvia. What we receive and keep is the result: the verified name, the kind of document, where it was issued, when it expires, and the last four characters of its number. Plaid is not used for banking, account balances, transactions or payments.
Billing, and the record of what a workspace is subscribed to.
Payments, subscriptions and tax
Takes payment and holds the authoritative record of a workspace’s plan, invoices and tax position.
Card numbers and security codes are entered directly into Stripe and never reach Plexvia.
plexvia.com is a separate surface from the product. These two see visitors to this site, and no workspace data.
CloudFront and S3
Serves plexvia.com, including the page you are reading.
The site is prerendered and reads published documents from our API exactly as any visitor would. It carries no workspace data.
Google Analytics
Measures how this website is used, so we know which pages are worth keeping.
On plexvia.com only. It is not part of the product, and it is never given the contents of a workspace.
HeyCatch analytics
Measures which pages a visitor reads and which ones end in a message to us, so we can tell what this site is actually for.
On plexvia.com only. It records no screen replay and never the words typed into a form, only that a form was sent. Like the line above it, it is not part of the product and is never given the contents of a workspace.
When a workspace connects its own email account, mail is sent and received through the host that workspace already chose. That relationship is the workspace’s, not ours, so the host is not our subprocessor. We hold the credentials, encrypted, so Plexvia can collect the mail on the workspace’s behalf.
We mention it because it is a real path your data takes, and a list that left it out would be accurate and still misleading.
Every provider here runs in more than one part of the world. Where each one processes data is a fact about how Plexvia is deployed, and the only acceptable evidence for it is the provider’s own console or a signed agreement. We are working through them, and each region appears on this page as it is confirmed.
If you are completing a data transfer assessment and need what has been confirmed so far, write to us and we will send it.
We update this page when a provider is added, replaced or removed, and the date at the top moves with it. If you would rather hear about a change than find it, write to us and we will tell you.
Write to ehlo@plexvia.com. A person reads it.