Back to vendors
C

Conveyor

Also known as: ConveyorAI, Conveyor Trust Center Agent

Visit site
Entry priceFree tier available; Business starts at $9,600 per year, billed annually (about $800 per month); Enterprise customFull pricing detail

Customer security review platform whose AI completes incoming questionnaires with cited answers and whose Trust Center Agent lets buyers self serve the whole review, including uploading a questionnaire and getting it answered without the vendor's team involved.

Conveyor works on customer security reviews from both ends. On the seller side, ConveyorAI ingests security questionnaires and completes them with cited answers drawn from a knowledge base of approved policies, documents and past responses. On the buyer side, an agent-powered Trust Center lets the customer self-serve, and the Trust Center Agent answers their questions directly inside the portal rather than leaving them to dig through an information dump.

That second half is the strategic idea. Trust centers that grow too large to navigate push enterprise buyers back to demanding a manual response or a call, which puts the security team back in the loop it was trying to escape. Conveyor's answer is to embed the AI into the portal so a buyer can simply ask, including uploading a full standard questionnaire and having it completed without a human on the vendor side ever touching it. The company calls this a touchless security review, and the trigger sits with someone outside the customer's own organization.

The agent operates across the channels the work actually arrives on: it processes cases, tickets and Slack messages carrying uploaded questionnaire files, triages what comes in, updates stakeholders on status, and asks follow-up questions when it needs more information. For responses that must be filled in someone else's system, a Chrome extension autofills questionnaires directly inside third-party customer portals rather than forcing copy and paste between windows.

An AI Connector built on the Model Context Protocol puts the same knowledge inside Claude, ChatGPT, Notion AI and other assistants, carrying each person's existing permissions and able to approve Trust Center access or update knowledge as well as answer questions. A separate RFP path adds document automapping, go/no-go and red flag identification, rules-based routing to subject-matter experts, in-document Word editing and version controls.

Underneath, a Knowledge Librarian monitors and cleans the corpus so answers stay current, and analytics cover trust center engagement, AI accuracy, RFP insights and revenue impact. Conveyor holds SOC 2 Type II audited by Linford & Company, published through its own trust center, with SSO, SCIM provisioning and role-based permissions at the enterprise tier and portal access governed by NDA gating, access groups and document watermarking.

Deployment is multi-tenant cloud with no region selection or self-hosted option. Audit logging is documented over the AI assistant channel but not over the touchless path, which is the run with no human in it. Pricing is usage-based rather than per-seat: a free trust center tier, a Business plan from $9,600 a year, and Enterprise quoted on volume.

Vendor details

Canonical URL

https://www.conveyor.com

Category

GTM / revenue agent

Subcategory

Customer security review and trust center automation

Funding status

Independent. Legal entity Conveyor Inc. Customers named on its own property include Atlassian, Carta, dbt Labs, Zapier, Lucid, Cvent, Sinch, Instructure, TrueContext and Temporal. No funding figure is published on the property; press reports a Series B in 2025.

Company status

independent

Use cases & customers

Primary use cases

security questionnaire automationhosted trust center and document sharingbuyer self-service security reviewRFP response drafting

Target customers

security and compliance teamsB2B SaaSenterprise

Deployment options

SaaScloud

Integrations

Named integrations across four classes, with the vendor stating explicitly that integrations carry no charge: Salesforce, delivered as a managed package, and HubSpot for CRM; Jira and Zendesk for ticketing; Slack for collaboration; DocuSign for NDA e-signature; and a published directory carrying more. The agent reads work out of those queues rather than only writing to them, picking up cases, tickets and Slack messages carrying questionnaire files, and reports security review effort back to Salesforce so the work ties to deals. Two further surfaces extend reach: a Chrome extension that autofills questionnaires inside third-party customer portals, and an MCP server at mcp.conveyor.com that connects Claude, ChatGPT, Notion AI, Atlassian Rovo, Glean and Cursor, carrying each user's existing Conveyor permissions and able to take actions as well as answer. A public API and developer documentation sit behind both.

In practice

A prospect's security team sends a 300 question standard questionnaire. They can upload it into your trust portal and the Trust Center Agent completes it, so nobody on your side opens the spreadsheet at all.

Your reps work inside Claude all day and keep interrupting security for one off answers. The Connector for Claude gives them cited answers and completed questionnaires without a handoff.

A questionnaire has to be filled inside the buyer's own portal. The browser extension autofills it in place rather than requiring answers to be copied between windows.

Agentic Index coverage score

9.0 / 14 capabilities · 64%

Integrations & Tool Calling Full

Breadth across classes, with Conveyor making a point of not charging for it. Named integrations span CRM in Salesforce, delivered as a managed package, and HubSpot; ticketing and ITSM in Jira and Zendesk; collaboration in Slack; and e-signature in DocuSign, with a published directory carrying more.

The agent reads work out of those systems rather than only writing to them, processing cases, tickets and Slack messages that arrive carrying questionnaire files, and reports security review effort back into Salesforce so the work ties to deals. A browser extension carries the platform into third-party portals and the MCP server carries it into AI assistants. Pricing is explicit that there are no charges for integrations, so the connector set is not a tier lever.

Sourceconveyor.com/integrations and conveyor.com/pricingread 2026-09-04

Workflow Orchestration Full

Agents handing work along a chain that runs from intake to a returned document, on both sides of the review. Inbound, sales triage sorts what arrives and the agent processes cases, tickets and Slack messages carrying questionnaire files end to end, updating stakeholders on status and asking follow-up questions when it needs more. The Knowledge Librarian maintains the corpus underneath.

On the RFP side the chain is longer and explicit: agentic document automapping, go/no-go and red flag identification, AI drafted answers grounded in briefs, deal docs and win themes, rules-based SME auto-assignment, in-document Word editing, and audit and version controls. On the buyer side the Trust Center Agent completes an uploaded questionnaire without anyone on the vendor side opening it. The pricing matrix names each agent as a separate capability.

Sourceconveyor.com/ai-agents-for-security-reviews and conveyor.com/pricingread 2026-09-04

Knowledge Grounding & RAG Full

Grounded on the customer's own approved security corpus, with the corpus actively maintained rather than merely stored. A centralized knowledge base holds security documentation, compliance policies, past answers and organizational knowledge, and Conveyor documents connecting the AI to any source, naming websites, shared drives, help centers and docs, so the material stays where teams keep it.

A Knowledge Explorer and an AI Librarian curate it, with Q&A management and multi-product answer tagging so the right posture is used for the right product line. Retrieval is described as a RAG engine rather than open generation, every answer cites its work, and Conveyor states plainly that a connected assistant answers only from approved content with the user's permissions attached rather than guessing from training data. The corpus also grows across reviews, and it remains the customer's content rather than agent memory.

Sourceconveyor.com/products/knowledge-management and conveyor.com/pricingread 2026-09-04

Human Oversight & Guardrails Partial

Review exists on the seller's side and is deliberately absent on the buyer's, which is the product's central design choice rather than an oversight. First-pass drafts are reviewable before they go back, the RFP path identifies red flags and runs go/no-go before work starts, rules-based auto-assignment routes questions to the named subject-matter expert and the AI notifies them, audit and version controls sit over RFP documents, and answers are bounded to approved content so the agent cannot draw on anything the team has not sanctioned. The flagship path removes the human by design.

Conveyor markets a touchless security review in which a buyer uploads a questionnaire into the trust portal and the Trust Center Agent completes and returns it without anyone on the vendor side opening it, and no approval gate, confidence threshold or hold is documented on that path. Access controls on the portal, NDA gating, access groups and domain-based approval automation govern who may see documents rather than what the agent may say.

Sourceconveyor.com/products/security-questionnaire-automation and conveyor.com/products/trust-centerread 2026-09-04

Security, Identity & Governance Full

Access control and compliance are both documented, with the access surface named as an entitlement rather than implied. Enterprise settings list enterprise roles and permissions as RBAC, and single sign-on with SCIM provisioning, and Conveyor supports user provisioning through Okta and other identity providers.

Those permissions propagate rather than stopping at the console: a person connecting an AI assistant through the MCP server sees only what their existing Conveyor role already allows, and revoking access in Conveyor revokes it for the assistant. Trust Center access is itself governed by access groups, domain-based approval automation, clickwrap NDA gating and auto-watermarking of downloaded documents.

Behind that sit SOC 2 Type II covering Security, Availability and Confidentiality, audited by Linford & Company LLP with reports available for review through Conveyor's own trust center at trust.conveyor.com, a published security policy and a responsible disclosure program, API keys scoped to least privilege, and infrastructure on Aptible Deploy, itself SOC 2 Type 2 and HITRUST validated. SSO, SCIM and RBAC sit on the Enterprise tier.

Sourcetrust.conveyor.com and conveyor.com/pricingread 2026-09-04

Observability & Auditability Partial

A genuine audit trail over one channel, and silence over the channel that matters most. Conveyor states that every question coming through a connected AI assistant is visible to the team via audit logs, giving a full picture of what is being asked and how it is being answered even when nobody on the team answered it, and answers carry citations back to approved sources.

Around that sit analytics on Trust Center engagement and requests, ConveyorAI performance and accuracy, RFP response insights, business and revenue impact, CSAT on Trust Center responses, and audit and version controls on RFP documents. The audit log is documented for the MCP assistant channel, and nothing extends it to the touchless path, the product's headline capability, in which a buyer uploads a questionnaire into the trust portal and the Trust Center Agent completes it with no vendor-side human involved. That is the run most in need of a reconstructable record and the one where none is documented.

Sourceconveyor.com/products/analytics and conveyor.com/pricingread 2026-09-04

Memory & State Persistence Not documented

A curated knowledge base, not agent memory. Past answers and security documentation persist in a centralized knowledge base that grows with each completed review, and the Knowledge Librarian monitors and cleans it so what is read back stays current. That is the customer's content, and a content store is not memory. No memory construct the agents write and read back as their own state, no per buyer or per engagement recall and no retention or forgetting control at the agent level is documented.

Sourceconveyor.com/products/knowledge-managementread 2026-10-01

Deployment & Data Residency Not documented

Multi-tenant cloud with no location or topology control offered. The only hosting choice on the pricing matrix is between a portal hosted by Conveyor on its own domain and a custom domain such as trust.companyname.com, which is branding rather than deployment control and does not move where anything runs. No region selection, EU or other in-region option, private cloud, VPC, single-tenant tier or on-premises route is documented.

Infrastructure runs on Aptible Deploy over AWS, which Conveyor describes as continuously audited and carrying ISO 27001, FedRAMP, DoD CSM and PCI DSS, but those are the provider's certifications and say nothing about a region the customer selects. Residency is a routine line in the very questionnaires the platform exists to complete, since its function is publishing and answering security posture for enterprise customers.

Sourcetrust.conveyor.com and conveyor.com/pricingread 2026-09-04

Prebuilt Agents, Templates & Packs Full

A named set of prebuilt agents, each a product doing its own job.

The pricing matrix lists Trust Center Agent, Knowledge Librarian, the questionnaire automation agent, the AI RFP responses agent, the portal browser extension and the sales triage agent as entitlements, and the Free plan carries the Trust Center while questionnaire automation and integrations sit on Business, so the buyer selects among them by plan.

Each stands without the others: the Trust Center Agent answers buyers in the portal, questionnaire automation completes incoming files, the RFP agent works bids, the librarian maintains the corpus.

Sourceconveyor.com/pricing and conveyor.com/ai-agents-for-security-reviewsread 2026-10-01

Triggers & Channel Coverage Full

Work comes in from several directions, and one of them is the buyer rather than the seller.

Inbound sources are cases, tickets and Slack messages carrying questionnaire files; Jira and Zendesk queues; questionnaires imported in any format; the browser extension picking up a questionnaire inside a third-party portal; connected AI assistants through the MCP server; and the buyer-facing trust portal, where a prospect uploads a standard questionnaire and the Trust Center Agent completes it with no action on the vendor side, work that arrives from outside the customer's organization.

Outbound, it returns completed documents in the original format, Slack and Salesforce updates, stakeholder and SME notifications, and answers inside the assistant a rep already uses.

Sourceconveyor.com/products/trust-center and conveyor.com/pricingread 2026-10-01

Model Flexibility & Routing Not documented

The customer does not choose the model and no provider is named. No model list, routing policy, per-agent selection or bring-your-own-key option is documented. Conveyor states only that it continuously improves its models and describes the engine as RAG-based, which is architecture rather than choice.

The connector page names Claude, ChatGPT, Notion AI, Atlassian Rovo, Glean and Cursor, but those are the assistants a customer already uses calling Conveyor through MCP.

That is the customer picking the interface that reads Conveyor, the opposite of choosing what powers the product; Conveyor makes the point itself, contrasting an assistant guessing from general training data against one drawing on Conveyor's approved knowledge base.

Sourceconveyor.com/products/ai-connector and conveyor.com/pricingread 2026-09-04

APIs, SDKs & MCP Extensibility Full

An MCP server that acts, a public API behind it, and published developer documentation for both. The AI Connector is a server built on the Model Context Protocol at mcp.conveyor.com/mcp, added as a custom connector through OAuth with no engineering work, and Conveyor names Claude, ChatGPT, Notion AI, Atlassian Rovo, Glean and Cursor as clients plus anything else supporting the standard.

It executes rather than only reading: a connected assistant answers from the approved knowledge base, pulls analytics and reports, and takes actions including approving Trust Center access and updating knowledge, with each person's existing Conveyor permissions carried through so the assistant sees only what that user may already see. A public API is a listed Enterprise entitlement alongside SSO and SCIM, and documentation sits at docs.conveyor.com with an MCP server reference. No SDK or client library is published.

Sourcedocs.conveyor.com/reference/mcp-server, conveyor.com/products/ai-connector and conveyor.com/pricingread 2026-09-04

Testing, Debugging & Optimization Partial

Measurement pointed at the agent as well as the outcome, and no comparison behind it. ConveyorAI performance and accuracy is a shipped analytics surface, so a customer reads how the agent itself is doing, alongside RFP response insights, Trust Center engagement and CSAT on responses the agent gave to buyers, and continuous data monitoring and cleaning runs against the corpus. Nothing compares configurations under control.

There is no scored evaluation set, benchmark suite, regression check when the knowledge base or instructions change, or sandbox before an answer reaches a buyer. Conveyor's published 95%+ accuracy figure is its own claim and the free-trial stress test is a pre-sales exercise, neither a mechanism the customer holds.

Sourceconveyor.com/products/analytics and conveyor.com/pricingread 2026-10-01

Browser & Computer Use Partial

A browser extension that fills questionnaires inside portals the vendor does not control.

Conveyor publishes a Chrome extension in two distinct modes on its pricing matrix: a browser extension for one-off search, and a browser extension for customer portals, the second of which autofills questionnaires directly inside third-party platforms rather than requiring answers to be copied between windows, and the portal extension is listed among the named agents with its own accuracy band.

Procurement and vendor-risk portals are the classic case of software with no programmatic interface. Coverage is limited to supported portals rather than general browser or computer control, with no headless session, virtual desktop or arbitrary navigation documented.

Sourceconveyor.com/pricing and the Conveyor Chrome Web Store listing; chromewebstore.google.com/detail/conveyor/djkpbjhiilodaficngfbddkhaendinhhread 2026-09-04

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-09-10·Agent capabilityVerified

Conveyor released its rebuilt Agentic Answer Engine, which uses sub-agents to plan, retrieve context, and iteratively generate complete answers for security questionnaires. The update also introduces an MCP-powered AI Connector for Trust Center visitors, exposes feedback data via API and MCP, automates question routing to experts, and adds a native SharePoint integration.

Bears on: Agent capability

View source
View all 1 change for Conveyor →Tracked since Sep 2026 · Verified from public vendor sources

Pricing

Free tier available; Business starts at $9,600 per year, billed annually (about $800 per month); Enterprise custom

credits, where one credit equals one organization with unlimited users from a domain, plus questionnaire and RFP volume

Free tierTrial available

What is public

Three plans, the free allowances, the feature gating between Free and Business and the Business starting rate are published; Trust Center and Questionnaire credits are named but not defined on the page.

Billing mechanics

Priced on the number of organizations that download documents or information from the trust center and on the number of questionnaires and RFPs processed by the AI. One credit equals one organization, covering unlimited users from that domain, an unusual unit because it tracks buyer-side demand rather than seller-side headcount. Annual commitment required; monthly billing is not offered.

Cost watchouts

The free tier excludes the questionnaire automation that is the main reason to buy, annual commitment is required with no monthly option, and credits are consumed per organization interacting with gated content

Variable cost rationale

The annual Business rate sets a floor, and credits consumed by trust center and questionnaire volume raise the bill with inbound buyer demand; scaling rates are unpublished.

Additional watchouts

The free tier deliberately excludes questionnaire automation and integrations, so it exercises the trust portal only and is not a trial of the core AI.

Overage / add-ons

Additional credits as organization and questionnaire volume grows; scaling rates are not published

Sales call required

Mixed (some tiers require a call)

Free / trial

Free plan at $0 per year with 10 trust center credits a month and up to 120 organizations, but no questionnaire automation and no integrations

Lowest paid plan

Business, from $9,600 a year billed annually

Commercial notes

Cost is metered in Trust Center and Questionnaire credits rather than seats, so the bill follows review volume rather than headcount.

Key ambiguities

Business is quoted as a starting rate, how credits are counted is not defined on the pricing page, and how credits scale above the entry allocation is not published.

Agentic Index verified 2026-10-01

Alternatives to Conveyor

The closest documented capability profiles to Conveyor among GTM and revenue agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Common Room9.0 / 14Fuller documented coverage on Prebuilt Agents, Templates & Packs
  • Demandbase9.0 / 14Fuller documented coverage on Prebuilt Agents, Templates & Packs
  • Gong9.0 / 14Fuller documented coverage on Prebuilt Agents, Templates & Packs
  • lemlist9.0 / 14Fuller documented coverage on Prebuilt Agents, Templates & Packs
  • Responsive9.0 / 14Fuller documented coverage on Human Oversight & Guardrails
  • SalesCloser.ai8.0 / 14A lighter documented profile than Conveyor

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.