Data Security

How we protect your business information at every step.

When you upload documents to your AI chatbot, you're trusting us with sensitive business information. We take that responsibility seriously. From the moment you upload a file to when your team queries it, security is built into every layer.

Our Security Approach

Data in Transit (Moving Data)

When you upload files or chat with your AI assistant, that information travels over the internet. We protect it during this journey.

What We Do:
  • HTTPS Encryption: All connections use TLS 1.2+ encryption. This is the same technology banks use to protect your online banking.
  • No Unprotected Connections: We reject any attempt to send data without encryption.
  • Secure Internal Communication: Even communication between our own systems is encrypted, not just connections from your browser.
In Simple Terms: Think of this like sending a letter in a locked box instead of a postcard. Nobody can read it while it's being delivered.

Data at Rest (Stored Data)

Your uploaded files sit in storage until you need them. We make sure they stay protected even when they're just sitting there.

What We Do:
  • AWS S3 Protected Storage: Your files are stored in Amazon's highly secure cloud storage (S3), used by millions of businesses worldwide.
  • Encryption with AWS KMS: Every file is encrypted using military-grade encryption keys managed by Amazon's Key Management Service.
  • Access Control: Files are locked down so only your logged-in users can access them. Even our support team cannot browse your files.
  • Google's Secure Servers: Your chatbot uses Google's File Search technology (RAG), so your information also benefits from Google's enterprise-grade security infrastructure.
In Simple Terms: Your files are locked in a digital safe, and only people with the right key (your login credentials) can open it.

Who Can Access Your Data?

We use Amazon Cognito to manage user identities and ensure only authorized people can access your chatbot.

Access Rules:
  • Login Required: No one can access your files or chatbot without logging in first.
  • User Isolation: Each user only sees their own data. Your employees cannot access another company's information.
  • Role-Based Access: You control who on your team can upload files, manage settings, or just chat with the AI.
  • Session Management: Sessions expire automatically for security, so even if someone leaves their computer unlocked, the session won't stay open forever.
In Simple Terms: It's like an office building where everyone needs an ID badge, and each badge only opens certain doors.

Google's AI Technology (RAG)

Your chatbot is powered by Google's File Search RAG (Retrieval-Augmented Generation) technology. This means your data benefits from Google's enterprise security.

What This Means:
  • Google's Infrastructure: Your information is processed using Google's AI, which is protected by the same security standards as Google Workspace and Google Cloud.
  • Private Processing: Your data is used only to answer your questions. It's not used to train Google's AI models for other customers.
  • Isolation: Each organization's data is kept completely separate.
In Simple Terms: Google powers the "brain" of your chatbot, but your data stays private to you, just like your Gmail is private even though Google runs the service.

What We Don't Log

We keep minimal logs—just enough to fix problems and keep the service running.

Privacy Protection:
  • No Content Logging: We don't log the actual contents of your files or your conversations with the AI.
  • System-Level Only: We track system performance (like "chatbot responded in 2 seconds") but not what you asked or what it answered.
  • Error Detection: If something breaks, we see error codes, not your sensitive data.
In Simple Terms: We track if the lights are on, but we don't record what you're saying in the room.

Common Security Questions

No. Your files are encrypted and access-controlled. Our support team cannot casually browse your files or conversations. We only have access to system-level information for troubleshooting.

Each organization's data is completely isolated. If one account were compromised, it would not give access to any other organization's data. Think of it like separate locked apartments in a building—breaking into one doesn't unlock the others.

No. Your uploaded files and conversations are used only to power your chatbot. They are not used to improve Google's AI for other customers or mixed with any other organization's data.

Your files are stored in AWS S3, a highly secure cloud storage service. We can configure storage in specific regions (like EU for European customers) to meet data residency requirements. Learn more about data location.

You can delete individual files at any time through your dashboard. If you want to delete your entire account, contact our support team and we'll permanently remove all your data from our systems, including backups. Learn more about data deletion rights.

Still Have Questions?

We're happy to discuss your specific security requirements.

View Compliance Info Data Protection Details