Join the early access program

You control access.
We protect your data.

Your agents work only with the permissions you give them. Your company’s data stays separate, and sensitive actions follow the approval rules you set.

GDPR / KVKK

Compliant

ISO/IEC 42001

Compliant

ISO 27001

Compliant

SOC 2 Type II

Planned

Data residency

European Union

Four layers of protection

Security isn't a feature. It's our foundation. Every layer of the Botonom platform is designed with defense in depth.

Encryption Everywhere

All data in transit is encrypted with TLS. Provider keys, OAuth tokens and API secrets are never stored as plain text and never reach the browser.

TLS for all data in transit
Provider keys and tokens stored encrypted
Bring your own model key (BYOK)
Strict Content Security Policy (CSP)

Access Control

Role-based access control with granular permissions. Every agent action, every sign-in and every configuration change is recorded.

Role-based access control (RBAC)
Two-factor authentication (2FA)
Sign in with Google and Microsoft
View and revoke active sessions

Data Isolation

Each workspace operates in a logically isolated environment. Your agents, conversations, and data are completely separated from other customers.

Logical tenant isolation
Conversations and knowledge base partitioned by tenant id
Per-company agent runtime context
No cross-tenant data access

Full Audit Trail

Comprehensive logging of every action across your workspace. Who did what, when, and from where, searchable and exportable for compliance reviews.

Durable audit records
User activity tracking
Agent action history
Exportable compliance reports

Compliance you can verify

Request our compliance documentation, data processing agreements (DPA) and security control documents whenever you need them.

GDPR / KVKK

COMPLIANT

Our practices are built to EU GDPR and Turkish KVKK principles: a defined data subject request process, a permanent data purge you can run from the dashboard, and an exportable audit trail.

ISO/IEC 42001

COMPLIANT

Our AI management system architecture is built on ISO/IEC 42001: human approval gates, an emergency stop, an audit trail and the right to be forgotten. A written AIMS policy is in place.

ISO 27001

COMPLIANT

Our information security management system is built to the ISO 27001 framework: access management, encryption, event logging, asset classification and supplier review.

SOC 2 Type II

PLANNED

Our controls follow the SOC 2 Trust Services criteria for security, availability and confidentiality. An independent Type II audit is on our plan.

CCPA

SUPPORTED

We serve California Consumer Privacy Act (CCPA) access, deletion and portability requests through the same data subject process.

Infrastructure hosted in the European Union

Your AI agents run on infrastructure designed for reliability, performance and security. Data residency is in the European Union.

Secure data center infrastructure

Cloud Infrastructure

Hosted in the AWS eu-central-1 (European Union) region.

Data Residency

Conversations, the knowledge base and uploaded files are held in the European Union region.

Access Revocation

Sessions, API keys and connected app access can be revoked from the dashboard at once.

Deploy Gate and Health Check

Every release to production passes a build and type check, and an automated health check runs after deployment.

Request and Form Protection

A strict content security policy, bot verification on form submissions and spam protection are applied.

Redundant Storage

Replication of data across multiple availability zones with automated backups.

Disaster Recovery

A 4-hour RTO and 1-hour RPO target, documented runbooks and regular failover drills.

Contractual SLA and Status Page

A contractual uptime commitment backed by service credits, and a public real-time status page.

DDoS Protection

Multi-layer DDoS mitigation at the edge with automated threat response.

24/7 On-Call Monitoring

Continuous infrastructure monitoring with automated alerting and an on-call engineering rota.

AI you can trust

Our commitment to responsible AI goes beyond compliance. These principles are built into every agent, every feature, every decision.

No Training on Your Data

Your conversations, documents, and business data are never used to train our AI models. Your data is yours, period.

Transparent Agent Behavior

Every tool the agent calls, the arguments it used and the result are recorded. That record is readable in the dashboard and exportable in a machine readable format.

Data Retention Controls

You can permanently purge your workspace's agent memory at any time, and export your audit trail for a date range you choose.

Human-in-the-Loop

The approval policy is chosen per agent: ask on every side effect, ask only on critical actions, or act alone behind a signed risk acceptance. Approval is a click; an agent cannot unlock itself.

Emergency Kill-Switch

Instant single-point shutdown freezes recurring background tasks, silences WhatsApp and Telegram channels, and drops active agent WebSocket sessions.

Right to be Forgotten and Data Purge

Permanently delete your workspace's entire agent conversation history, memory windows and knowledge base vectors from the dashboard. The purge also drops live sessions and leaves its own audit record.

Algorithmic PII Masking

National ID, credit card and IBAN values are validated by checksum and masked before they reach memory.

A continuous security rhythm

Security is not a one-time checkbox. Our operations team works to a disciplined rhythm of testing, review and improvement.

Every turn

Approval Gate

Side-effecting actions stop according to the agent's approval policy

Every deploy

Build and Type Check

Every release to production is built and type checked in CI

After deploy

Health Check

An automated availability check runs after deployment

Daily

Availability Monitoring

Page availability and performance are measured daily

Continuous

Vulnerability Scanning

Automated SAST and DAST scans on every deployment

Weekly

Dependency Audit

Known-CVE scanning and updates across all packages

Quarterly

Access Review

Reviewing and revoking permissions that are no longer needed

Annual

Penetration Test

Third-party penetration test with a full remediation cycle

Enterprise-grade security features

For organisations that need advanced controls, dedicated infrastructure and hands-on compliance support. Available on our Enterprise plan.

Talk to Sales

Role-Based Authority

Each agent sees only the capabilities and data it was granted

Per-Agent Approval Policy

Ask on every action, ask on critical actions, or a signed risk acceptance

Audit Trail Export

Download a machine readable audit file for a date range you choose

Right to be Forgotten

Permanently purge the workspace's agent memory

Bring Your Own Model Key

Run on your own provider account

Data Processing Terms

A data processing agreement prepared on request, negotiated with your legal team

Single Sign-On (SSO)

Okta, Azure AD, Google Workspace and custom SAML providers

SCIM Provisioning

Automated user lifecycle management

IP Allowlist

Restricting access to approved network ranges

Dedicated Infrastructure

Isolated compute and storage on request

Data Residency Choice

Choose where your data is stored: EU, US or APAC

On-Premise Deployment

Run on your own infrastructure or in an isolated environment

Vendor Security Questionnaire

Pre-filled SIG / CAIQ responses

Security questions

Where is my data stored?

By default, data is stored in the AWS European Union (eu-central-1) region. Enterprise customers can request a different data location.

Do you use my data to train AI models?

No. We never use customer data, conversations, or uploaded documents to train, fine-tune, or improve our AI models. Your data is used solely to provide the service you've configured.

What happens if an agent makes a mistake?

Every agent action is recorded in the audit trail. You can review actions, stop the agent instantly with one click, and tighten the approval policy so every side effect goes through an approval gate.

Which compliance documents can you share?

Under an NDA we can share our written AI management system (AIMS) policy, our human approval gate architecture document, our security control documentation and an anonymised sample audit trail export. The compliance cards above show our current certification status.

How do I report a security vulnerability?

We run a responsible disclosure programme. Please report vulnerabilities to info@botonom.com. We review reports as quickly as we can and get back to the reporter.

Do you support on-premise deployment?

Yes. Enterprise customers can run Botonom on their own infrastructure. Contact us to discuss deployment scope and your data residency requirement.

Questions about security?

Our security team is glad to answer questions, walk you through our practices and share the compliance documentation we hold.