Security & privacy

How Covendri keeps your computers and data safe

Covendri's AI works on your team's computers and, if you connect them, your company's mailboxes and WhatsApp number, so we designed it to be limited, supervised and accountable from day one. Here is how, in plain language.

A person approves anything risky

Installing software, closing apps, running scripts and restarting always need an admin.

Your screen only with consent

Screen control is optional, off by default and approved by the employee for each task. Never camera, microphone or passwords.

Everything is on the record

Every action and decision lands in your audit log, and each company's data is kept separate.

The AI can only use typed, risk-rated tools

Covendri's AI doesn't get a command line on your computers. It can only call a fixed set of tools that the Covendri Agent provides, such as "check disk usage" or "clear the print queue". Each tool has a defined purpose, defined inputs, and a risk level:

Risk levelWhat it meansExamples
ReadLooks, doesn't change anything. Runs automatically.Disk usage, network and Wi-Fi checks, installed software, update status, security settings
SafeLow-impact fixes. Run automatically unless you require approval.Clear a print queue, flush DNS, clear temporary files, reset an app's camera permission
ApprovalHigh-impact. Never runs without an admin saying yes.Install or remove software, close apps, restart services, run scripts, restart the computer

Approvals and your rules are enforced outside the AI

The rules that decide what may run are applied by Covendri's servers, not by the AI model. That means a cleverly worded request, or a confused model, can't skip an approval.

  • The server sets the risk floor. A device can't lower a tool's risk level, and tools the server doesn't recognize always need approval.
  • High-impact actions always wait for a person. The request shows what the AI wants to do, on which device, and why. Approve it, or decline with a note.
  • You can tighten the rules. Admins can require approval for safe fixes too, or turn off whole classes of actions.

Screen control and what the agent never does

IT support works without seeing the screen. Covendri can also help with routine tasks, such as downloading invoices from a supplier portal, by using the screen or a Chrome tab. That feature is off unless an admin turns it on, and only then does the Mac ask for the Screen Recording and Accessibility permissions.

  • The employee approves each task, and a banner shows while Covendri is working. Pressing Esc or Stop ends it immediately.
  • Covendri asks before anything that sends, buys, pays, deletes or submits.
  • It refuses to type into password fields and stays out of password managers, banking sites and security settings.
  • Every step is logged with a small screenshot that admins and the employee can see. Screenshots are deleted after 24 hours by default.

The agent never uses the camera or microphone and never reads saved passwords.

It does run with administrator rights so it can diagnose and fix system problems. On a Mac, we also recommend granting Full Disk Access, which lets it see what is using storage and clear app caches. It still works without it, with less visibility. Process details are collected with command-line secrets redacted.

Email, WhatsApp and the assistant features

Beyond IT support, Covendri can help with email, quotes and everyday work. Each of these features only works with what your admin connects and allows.

  • Outlook (Microsoft 365). Your Microsoft 365 admin connects Covendri by granting admin consent to app permissions for reading and writing mail, sending mail and listing users. Covendri works only in the mailboxes your admin adds to its list, and our server refuses any other mailbox. You can also restrict the app in Exchange to those mailboxes.
  • Gmail. A Google Workspace super admin connects it with domain-wide delegation, or a person connects their own Gmail through Google's consent screen. It follows the same mailbox list and modes as Outlook. Refresh tokens for personal Gmail are encrypted at rest.
  • WhatsApp Business. Connects your company number through Meta's WhatsApp Business Cloud API, with the same draft and approval modes as email. Access tokens are encrypted at rest and every incoming webhook's signature is verified.
  • You choose how replies go out. For each mailbox or number: off, draft only (the reply is saved as a draft and a person sends it), or send after approval (Covendri sends only after someone approves it). Covendri never sends on its own.
  • Email text is kept briefly. The text of emails and suggested replies is deleted after 30 days by default, and admins can change that. Sender, subject and dates are kept up to about 90 days longer so the same email isn't handled twice, then deleted.
  • Teach Covendri. An admin can import past email or exported WhatsApp chats so Covendri learns your answers, prices and tone. Names, email addresses, phone numbers, ID, booking and bank details are automatically removed where they can be detected before the AI reads the text. Nothing learned is used until an admin approves it, and the copied text is deleted when the import ends, within 48 hours at most.
  • Quotes and images. Quotes are built from your own templates and go out only through the same draft or approval flow. Images are created with an image model on Azure OpenAI Service, subject to Azure's content filters, and stored in your workspace.

Tool output, messages and web content are treated as untrusted

Error messages, log files, emails, WhatsApp messages, web pages and screen contents can contain text written by anyone, including text designed to trick an AI ("prompt injection"). Covendri treats all of it as data to analyze, never as instructions to follow. And because approvals and sending modes are enforced on the server, even a successful trick can't unlock a high-impact action or send a message on its own.

Web search and research. Covendri can search the web, for example to look up an error code or to find hotels, tours and prices with links to its sources. Searches go through the web search tool in Azure OpenAI Service, which uses Grounding with Bing Search, a separate Microsoft service with its own terms. Covendri is designed to write search queries without names, contact details or other personal data, and prices found online are marked to be checked before use. Your admin can turn web search on or off for your workspace.

Every action is audited

Each request, every change made on a device, and every approval and decline is recorded in your workspace's audit log, along with who or what performed it and when. Admins can also open any request and see the full conversation and every step the AI took, including read-only checks.

Device connections

  • Outbound only. Each computer connects out to Covendri over an encrypted connection. You don't open firewall ports or set up a VPN.
  • A unique identity per device. Each enrolled computer gets its own secret. We store only a one-way hash of it, so a database leak wouldn't reveal device credentials.
  • Enrollment by token. Devices join your workspace with an enrollment token created by an admin in the dashboard.

Your data

  • Isolated per company. Every workspace's devices, requests, knowledge base and audit log are kept separate. Knowledge learned from your fixes is used only in your workspace.
  • Hosted on Microsoft Azure in the United States. AI processing and image generation use Azure OpenAI Service.
  • Only what's needed. Device diagnostics, the text of help requests, screenshots people choose to attach, and account details (name and email). If you connect them, messages in the mailboxes and WhatsApp number you allow. Detailed device health metrics are kept for 7 days.
  • Never sold. We don't sell your data or use it for advertising.
  • Deletion on request. Email support@covendri.com to have your workspace's data deleted.

For the full details, read our Privacy Policy.

Sign-in and access

  • Sign in with Microsoft, Google, or email and password. Accounts are linked only by email addresses that have been proven to belong to the person.
  • Role-based access. Employees see their own help requests and only the mailboxes they're allowed to use. Admins see their company's devices, requests, approvals, audit log and knowledge base.
  • Reviewed workspaces. During early access, every new workspace is reviewed before it's activated.
  • Secure sessions. The dashboard uses a secure, HTTP-only session cookie that expires automatically.

Where we are today

Covendri is in early access. We have not completed third-party audits or certifications such as SOC 2, and we don't claim to. If your business needs more detail about our controls, or has specific compliance requirements, email us and we'll answer honestly.

Report a vulnerability

If you believe you've found a security issue in Covendri, please email support@covendri.com with the details and steps to reproduce. Please give us a reasonable chance to fix it before sharing it publicly. We appreciate responsible disclosure.