Collect only the business details needed, reveal each lead to exactly one customer, and keep platform and customer each accountable for their own systems.
AIViral is operated by Ai Viral Sweden AB, a Swedish limited company (org. no. 559433-0952). Contact: support@aiviral.com.
Security begins with less data
Every extra field and every extra recipient is extra risk. Our architecture is built around minimization: we collect only the business contact details and conversation context needed to qualify and deliver a lead, and nothing more.
A lead's contact details are revealed exactly once: to the single customer the lead is delivered to. There is no browsing of other customers' leads, and no lead is ever sold twice.
Identity and access control
Access follows least privilege. Staff access to production systems is role-based, individually authenticated and logged; unused access is removed promptly. Customer accounts are isolated from one another, and each account can only reach the leads delivered to it.
Account credentials are the customer's responsibility to protect — treat them like passwords, and contact us immediately if you suspect compromise so we can revoke and reissue.
Encryption and secrets
Data is encrypted in transit using modern TLS and encrypted at rest in our storage systems. Service credentials and keys are kept outside source code in managed secret storage, with access limited to the systems that need them.
Exports and backups receive the same treatment as primary records: restricted access, controlled retention and secure deletion at end of life.
Payment security
Card and payment details are handled entirely by our payment provider over their certified infrastructure — they never touch our servers. Wallet balances and transactions are recorded in an append-only ledger, so every charge and credit can be traced.
Fraud and abuse prevention
A hot leads service only works if the leads are real. Every response is screened for fabricated, automated and duplicated patterns before it reaches a dashboard, and lead assignment is reviewed by our team. Accounts involved in fraud are suspended.
Monitoring and incident response
Production systems are logged and monitored for anomalies, with vulnerability management and dependency updates as ongoing practice. Backups are taken and restoration is tested.
If a suspected personal-data incident occurs, our process is to contain it, preserve evidence, assess the affected data and notify affected customers — and authorities where the law requires — without undue delay. Each party remains responsible for its own notification assessment as controller.
Service providers
The providers we use for hosting, security, payments and support are reviewed before engagement and governed by written agreements; they may process data only on our instructions. Where the law requires it, the current subprocessor list and change process are maintained in the data-processing terms.
