Skip to contentTelvory

Security and data residency

What protects your customers, in plain words — where their data lives, and what we do not claim.

Last reviewed 26 September 2026.

Where your data lives, and how it's protected

Telvory runs in Dubai on Microsoft Azure (UAE North). In plain words:

  • Your data lives in Dubai, on Microsoft Azure (UAE North): the servers that run Telvory, the database, the relay for blocked connections, and session recordings.
  • Live screen, audio and video are encrypted in transit by WebRTC and pass directly between the two machines — nothing is kept unless you switch recording on.
  • Session recordings are encrypted at rest and deleted at the end of the retention period you set, from 1 to 90 days.
  • File contents are never stored on our servers; only the name, size and outcome of a transfer are recorded.
  • Each workspace's data is separated by row-level security in PostgreSQL, and that isolation is tested on every change.

Azure UAE North is Microsoft's Dubai region. It is in the United Arab Emirates, not in Saudi Arabia.

How it is protected

Consent

A customer joining a session sees a consent screen that names the technician and their organisation, says plainly that we cannot vouch for the individual, and lists what is being asked for. With the helper they accept once for the session — view, control, files and audio together — and can pause or end it at any moment. A browser session goes further: screen share, control, file transfer, clipboard, audio and recording are each a separate grant. On an unattended machine consent is given once, when the agent is installed: we record who gave it — the person at the desk, or the administrator who deployed the agent — when, and for which capabilities, and it can be withdrawn from the consent register. After that a technician connects without prompting the person at the desk, unless your workspace policy asks them first.

Audit trail

Sessions, consents, actions on each machine, billing changes and admin actions are written to an append-only audit log for each workspace, which your owners can read and export. Each workspace's entries are chained by hash, so an entry that was changed or removed shows up when the chain is checked. You can also stream every entry, as it is written, to your own SIEM through a signed webhook. When our own staff need to open your workspace to help, they must give a reason, their access ends by itself within four hours, and every step they take is written to your audit log.

Workspace isolation

Every workspace's data is separated by row-level security in PostgreSQL and enforced by tests that run on every change — isolation is tested, not assumed.

Access control

Technicians sign in with email and password or with a Google or Microsoft account, and protect their account with authenticator-app MFA. Owners and admins can require MFA of everyone in the workspace, or only of chosen roles — a member without it is asked to set it up before they can continue. Turn on Secure Connect to require a fresh MFA check before any unattended connection, restrict the workspace to your office IP ranges, end idle unattended sessions automatically, and build custom roles over a fixed permission catalogue. Ten wrong passwords within fifteen minutes pause sign-in for that address.

Recording

Recording is off unless your workspace policy allows it, and even when the policy says always, the customer must agree. A visible indicator shows for the whole recording. The recording is made in the technician's browser and kept for the retention period you set, from 1 to 90 days.

Privacy operations

A privacy console for erasure requests and a breach register, the consent register, and a retention policy for each kind of data — chat transcripts, file-transfer records, session reports and the audit log — with every purge logged. Telvory is built with the Saudi Personal Data Protection Law (PDPL) in mind; that is a design goal, not a certification.

Agent and helper

The Windows agent runs as a service that resists being stopped, and uninstalling an enrolled machine needs your workspace's authorisation. The customer helper runs with ordinary user rights and removes itself after the session.

What we do not claim yet

So you don't have to find out later:

  • We do not currently hold ISO 27001, SOC 2, a Saudi NCA certification or any similar certification. Ask us for our current controls.
  • We do not host inside Saudi Arabia. Our servers are in the UAE.
  • Transactional email and platform secrets are not in the UAE yet — see the table above.
  • We make no contractual uptime commitment: Telvory runs in a single Azure region today.
  • Company single sign-on (SAML 2.0) is available per workspace: sign-in starts from Telvory, and a workspace can require it. Automatic user provisioning (SCIM 2.0) is available too — your identity provider adds, updates and removes members, only for addresses in your single sign-on domains. Accounts are not created at first sign-in: people join by invitation or through SCIM.
  • The PDPL is a design goal, not an assessment: no regulator or auditor has reviewed us.

Services we rely on

The third parties that handle data for Telvory, and what for.

Microsoft Azure
Hosting and session recordings in UAE North (Dubai); transactional email and platform secrets in Europe.
Cloudflare
DNS for telvory.app.
Moyasar
Card payments in Saudi Arabia, once online payment is switched on.
Google and Microsoft
Only when a technician chooses to sign in with that account.
SMS gateway (Unifonic or Twilio)
Only when a technician sends a session invitation by SMS.

See it on your own machines

Create a free workspace and run an attended session in minutes, or talk to us about a larger fleet.

Security & data residency · Telvory