Built so that your security team says yes.
Support conversations hold your customers' most personal details. Here is how BotableX keeps them yours, in plain language, without claims we cannot back.
-
Strict tenant isolation
Every channel, bot, Knowledge Bank, conversation, memory and log belongs to exactly one organization. The organization is bound to the identity token, never to a request header, so a request cannot ask for another tenant's data. Cross-tenant access exists only for platform administration and is always audited.
-
Encryption in transit and at rest
TLS 1.2 or higher everywhere. Attachments and sensitive fields are encrypted at rest with a key per organization. Secrets live in a managed vault, never in code or configuration files, and a production service refuses to start if a required secret is missing.
-
An audit log you can trust
Every security, operational and business event is written to an append-only, tenant-scoped audit log with daily indices. Takeovers, guidance, configuration changes and administrator access are all there, searchable and exportable. Raw personal data is never written to logs.
-
Hosted in the European Union
BotableX runs on Microsoft Azure in an EU region, behind a web application firewall, with geo-redundant storage and separate staging and production environments. Infrastructure is defined as code and deployed through reviewed pipelines.
-
Humans stay in control
The bot cannot hand a conversation off, cannot change its own behavior without approval, and can be set to draft-only on email. A documented emergency stop halts all outbound messages platform-wide, per organization, or per channel, and every channel has its own switch.
-
Privacy by design
End customers are identified by opaque, per-organization identifiers. Anonymous visitor memories are deleted after 30 days and identified customer memories after 180. Importing historical tickets requires an explicit confirmation of your lawful basis.
Controls in detail
For the questionnaire. Ask us for anything not listed here and we will answer plainly, including "not yet".
- Authentication
- Short-lived signed tokens for staff and customers, refresh with revocation, bcrypt-hashed passwords
- Access control
- Role-based permissions: Platform Admin, Admin, Senior Agent, Agent, with a fine-grained permission catalogue
- Webhooks
- Inbound webhooks from channel providers are signature-verified before processing
- Widget security
- Allowed-domain lists per channel; optional server-issued identity or session so nothing that can start a conversation reaches the browser
- Reliability
- Event-driven services with retries and circuit breakers, real-time delivery over a scaled-out backplane, append-only transcripts
- Traceability
- A transaction id on every request, carried through every service and into the audit log
What we do not claim
We do not currently hold a SOC 2 or ISO 27001 certification, we do not offer single sign-on, and uploaded files are not scanned for malware. We would rather you hear that from us than discover it later. Ask about our roadmap for each.