🎉Join the early access program
SECURITY & TRUST

Background-checked,
NDA-signed agents

Every agent you hire passes our rigorous security clearance. Your data is encrypted, isolated, and never used for model training. Enterprise-grade protection, regardless of your plan.

SOC 2 Type II

Planned

GDPR / KVKK

In progress

ISO 27001

Planned

Uptime

Target 99.9%

SECURITY PILLARS

Four layers of protection

Security isn't a feature. It's our foundation. Every layer of the Botonom platform is designed with defense in depth.

Encryption Everywhere

All data is encrypted at rest with AES-256 and in transit with TLS 1.3. Database fields containing sensitive information use application-level encryption with customer-specific keys.

AES-256 encryption at rest
TLS 1.3 for all data in transit
Application-level field encryption
Customer-managed encryption keys (Enterprise)

Access Control

Role-based access control with granular permissions. Every agent action, every user login, every configuration change: logged and auditable.

Role-based access control (RBAC)
Multi-factor authentication (MFA)
SSO / SAML 2.0 support (Enterprise)
IP allowlisting

Data Isolation

Each workspace operates in a logically isolated environment. Your agents, conversations, and data are completely separated from other customers.

Logical tenant isolation
Dedicated database schemas
Isolated agent execution environments
No cross-tenant data access

Full Audit Trail

Comprehensive logging of every action across your workspace. Who did what, when, and from where, searchable and exportable for compliance reviews.

Immutable audit logs
User activity tracking
Agent action history
Exportable compliance reports
COMPLIANCE

Compliance you can verify

Our agents meet the highest standards. Request audit reports, DPAs, and compliance documentation at any time.

SOC 2 Type II

PLANNED

On our roadmap. We are building toward an independent SOC 2 Type II audit of our security, availability, and confidentiality controls.

GDPR / KVKK

IN PROGRESS

We are aligning our practices with the EU GDPR and Turkey's KVKK, including Data Processing Agreements (DPA) for customers.

CCPA

PLANNED

Planned support for California Consumer Privacy Act data access, deletion, and portability requests.

ISO 27001

PLANNED

On our roadmap. Our information security management system is being aligned to the ISO 27001 standard.

INFRASTRUCTURE

Built on world-class infrastructure

Your AI agents run on infrastructure designed for reliability, performance, and security. Multi-region deployment ensures low latency and high availability worldwide.

Secure data center infrastructure

Cloud Infrastructure

Hosted on AWS with multi-region availability. Auto-scaling ensures your agents perform under any load.

Redundant Storage

All data replicated across multiple availability zones with automated backups every 6 hours.

Disaster Recovery

RTO of 4 hours and RPO of 1 hour. Tested quarterly with full failover exercises and documented runbooks.

99.9% Uptime SLA

Backed by a contractual SLA with service credits. Real-time status monitoring at status.botonom.com.

DDoS Protection

Multi-layer DDoS mitigation with rate limiting, traffic analysis, and automatic threat response.

24/7 Monitoring

Automated alerting and on-call engineering teams monitor infrastructure health around the clock.

RESPONSIBLE AI

AI you can trust

Our commitment to responsible AI goes beyond compliance. These principles are built into every agent, every feature, every decision.

No Training on Your Data

Your conversations, documents, and business data are never used to train our AI models. Your data is yours, period.

Transparent Agent Behavior

Every decision your AI agent makes is logged and explainable. No black boxes. You always know what happened and why.

Data Retention Controls

Configure how long data is retained in your workspace. Set automatic deletion policies or export everything at any time.

Human-in-the-Loop

Agents can be configured to escalate sensitive decisions to human operators. You control the autonomy level.

SECURITY OPERATIONS

Continuous security cadence

Security isn't a one-time checkbox. Our operations team runs on a disciplined cadence of testing, auditing, and improvement.

Continuous

Vulnerability Scanning

Automated SAST/DAST scans on every deployment

Weekly

Dependency Audits

Automated checks for known CVEs in all packages

Quarterly

Access Reviews

Review and revoke unnecessary permissions

Annually

Penetration Testing

Third-party pen test with full remediation cycle

Planned

SOC 2 Audit

Independent audit of controls and processes, on our roadmap

ENTERPRISE

Enterprise-grade security features

For organizations that need advanced controls, dedicated infrastructure, and hands-on compliance support. Available on our Enterprise plan.

Talk to Sales

Single Sign-On (SSO)

Okta, Azure AD, Google Workspace, custom SAML

SCIM Provisioning

Automated user lifecycle management

Custom DPA

Tailored Data Processing Agreement for your legal team

IP Allowlisting

Restrict access to approved network ranges

Dedicated Infrastructure

Isolated compute and storage on request

Penetration Testing

Annual third-party pen tests; reports available under NDA

Custom Data Residency

Choose where your data is stored: US, EU, or APAC

Vendor Security Questionnaire

Pre-filled SIG/CAIQ available on request

Common security questions

Where is my data stored?

All data is stored in AWS data centers. By default, data resides in US-East (Virginia). Enterprise customers can choose EU (Frankfurt) or APAC (Sydney) residency.

Do you use my data to train AI models?

No. We never use customer data, conversations, or uploaded documents to train, fine-tune, or improve our AI models. Your data is used solely to provide the service you've configured.

What happens if an agent makes a mistake?

Every agent action is logged in an immutable audit trail. You can review, undo, or escalate any action. Agents can be configured with confidence thresholds that trigger human review for uncertain decisions.

Can I get your SOC 2 report?

Yes. Our SOC 2 Type II report is available to customers and qualified prospects under a standard NDA. Contact our security team or your account manager to request a copy.

How do I report a security vulnerability?

We maintain a responsible disclosure program. Please report vulnerabilities to security@botonom.com. We acknowledge reports within 24 hours and aim to resolve critical issues within 72 hours.

Do you support on-premise deployment?

Yes. Enterprise customers can deploy Botonom on their own infrastructure: AWS, Azure, GCP, or bare-metal. This includes air-gapped environments for maximum data sovereignty.

LEARN MORE

Questions about security?

Our security team is happy to answer your questions, walk through our practices, or provide compliance documentation for your review.