You control access.
We protect your data.
Your agents work only with the permissions you give them. Your company’s data stays separate, and sensitive actions follow the approval rules you set.
GDPR / KVKK
Compliant
ISO/IEC 42001
Compliant
ISO 27001
Compliant
SOC 2 Type II
Planned
Data residency
European Union
Four layers of protection
Security isn't a feature. It's our foundation. Every layer of the Botonom platform is designed with defense in depth.
Encryption Everywhere
All data in transit is encrypted with TLS. Provider keys, OAuth tokens and API secrets are never stored as plain text and never reach the browser.
Access Control
Role-based access control with granular permissions. Every agent action, every sign-in and every configuration change is recorded.
Data Isolation
Each workspace operates in a logically isolated environment. Your agents, conversations, and data are completely separated from other customers.
Full Audit Trail
Comprehensive logging of every action across your workspace. Who did what, when, and from where, searchable and exportable for compliance reviews.
Compliance you can verify
Request our compliance documentation, data processing agreements (DPA) and security control documents whenever you need them.
GDPR / KVKK
COMPLIANTOur practices are built to EU GDPR and Turkish KVKK principles: a defined data subject request process, a permanent data purge you can run from the dashboard, and an exportable audit trail.
ISO/IEC 42001
COMPLIANTOur AI management system architecture is built on ISO/IEC 42001: human approval gates, an emergency stop, an audit trail and the right to be forgotten. A written AIMS policy is in place.
ISO 27001
COMPLIANTOur information security management system is built to the ISO 27001 framework: access management, encryption, event logging, asset classification and supplier review.
SOC 2 Type II
PLANNEDOur controls follow the SOC 2 Trust Services criteria for security, availability and confidentiality. An independent Type II audit is on our plan.
CCPA
SUPPORTEDWe serve California Consumer Privacy Act (CCPA) access, deletion and portability requests through the same data subject process.
Infrastructure hosted in the European Union
Your AI agents run on infrastructure designed for reliability, performance and security. Data residency is in the European Union.
Cloud Infrastructure
Hosted in the AWS eu-central-1 (European Union) region.
Data Residency
Conversations, the knowledge base and uploaded files are held in the European Union region.
Access Revocation
Sessions, API keys and connected app access can be revoked from the dashboard at once.
Deploy Gate and Health Check
Every release to production passes a build and type check, and an automated health check runs after deployment.
Request and Form Protection
A strict content security policy, bot verification on form submissions and spam protection are applied.
Redundant Storage
Replication of data across multiple availability zones with automated backups.
Disaster Recovery
A 4-hour RTO and 1-hour RPO target, documented runbooks and regular failover drills.
Contractual SLA and Status Page
A contractual uptime commitment backed by service credits, and a public real-time status page.
DDoS Protection
Multi-layer DDoS mitigation at the edge with automated threat response.
24/7 On-Call Monitoring
Continuous infrastructure monitoring with automated alerting and an on-call engineering rota.
AI you can trust
Our commitment to responsible AI goes beyond compliance. These principles are built into every agent, every feature, every decision.
No Training on Your Data
Your conversations, documents, and business data are never used to train our AI models. Your data is yours, period.
Transparent Agent Behavior
Every tool the agent calls, the arguments it used and the result are recorded. That record is readable in the dashboard and exportable in a machine readable format.
Data Retention Controls
You can permanently purge your workspace's agent memory at any time, and export your audit trail for a date range you choose.
Human-in-the-Loop
The approval policy is chosen per agent: ask on every side effect, ask only on critical actions, or act alone behind a signed risk acceptance. Approval is a click; an agent cannot unlock itself.
Emergency Kill-Switch
Instant single-point shutdown freezes recurring background tasks, silences WhatsApp and Telegram channels, and drops active agent WebSocket sessions.
Right to be Forgotten and Data Purge
Permanently delete your workspace's entire agent conversation history, memory windows and knowledge base vectors from the dashboard. The purge also drops live sessions and leaves its own audit record.
Algorithmic PII Masking
National ID, credit card and IBAN values are validated by checksum and masked before they reach memory.
A continuous security rhythm
Security is not a one-time checkbox. Our operations team works to a disciplined rhythm of testing, review and improvement.
Approval Gate
Side-effecting actions stop according to the agent's approval policy
Build and Type Check
Every release to production is built and type checked in CI
Health Check
An automated availability check runs after deployment
Availability Monitoring
Page availability and performance are measured daily
Vulnerability Scanning
Automated SAST and DAST scans on every deployment
Dependency Audit
Known-CVE scanning and updates across all packages
Access Review
Reviewing and revoking permissions that are no longer needed
Penetration Test
Third-party penetration test with a full remediation cycle
Enterprise-grade security features
For organisations that need advanced controls, dedicated infrastructure and hands-on compliance support. Available on our Enterprise plan.
Talk to SalesRole-Based Authority
Each agent sees only the capabilities and data it was granted
Per-Agent Approval Policy
Ask on every action, ask on critical actions, or a signed risk acceptance
Audit Trail Export
Download a machine readable audit file for a date range you choose
Right to be Forgotten
Permanently purge the workspace's agent memory
Bring Your Own Model Key
Run on your own provider account
Data Processing Terms
A data processing agreement prepared on request, negotiated with your legal team
Single Sign-On (SSO)
Okta, Azure AD, Google Workspace and custom SAML providers
SCIM Provisioning
Automated user lifecycle management
IP Allowlist
Restricting access to approved network ranges
Dedicated Infrastructure
Isolated compute and storage on request
Data Residency Choice
Choose where your data is stored: EU, US or APAC
On-Premise Deployment
Run on your own infrastructure or in an isolated environment
Vendor Security Questionnaire
Pre-filled SIG / CAIQ responses
Security questions
Where is my data stored?
By default, data is stored in the AWS European Union (eu-central-1) region. Enterprise customers can request a different data location.
Do you use my data to train AI models?
No. We never use customer data, conversations, or uploaded documents to train, fine-tune, or improve our AI models. Your data is used solely to provide the service you've configured.
What happens if an agent makes a mistake?
Every agent action is recorded in the audit trail. You can review actions, stop the agent instantly with one click, and tighten the approval policy so every side effect goes through an approval gate.
Which compliance documents can you share?
Under an NDA we can share our written AI management system (AIMS) policy, our human approval gate architecture document, our security control documentation and an anonymised sample audit trail export. The compliance cards above show our current certification status.
How do I report a security vulnerability?
We run a responsible disclosure programme. Please report vulnerabilities to info@botonom.com. We review reports as quickly as we can and get back to the reporter.
Do you support on-premise deployment?
Yes. Enterprise customers can run Botonom on their own infrastructure. Contact us to discuss deployment scope and your data residency requirement.
Questions about security?
Our security team is glad to answer questions, walk you through our practices and share the compliance documentation we hold.

