Your customers' conversations deserve real protection
Security is a set of defaults, not a checkbox. This is how SupportAi is built and run.
Encryption everywhere
TLS 1.2+ on every connection. Databases and object storage encrypted at rest. API keys and channel tokens are hashed or stored encrypted and never shown twice.
Workspace access control
Owner, admin, agent and viewer roles. Invitations expire, memberships are auditable, and API keys are scoped (read / write / chat) and revocable instantly.
AI guardrails
Prompt-injection detection, blocked topics, system-prompt leak checks and a configurable fallback answer. Custom actions only ever call the endpoints you define.
Your data trains your agent only
Content you upload is used solely to answer your customers. We do not train foundation models on your data, and model providers are used under their zero-retention API terms.
Data residency & retention
Hosted in the UK/EU on our Kubernetes cluster. Delete a bot and its sources, embeddings and conversations go with it; delete your account and everything is purged.
Signed integrations
Outbound webhooks are HMAC-SHA256 signed with per-endpoint secrets. Inbound Slack, WhatsApp and email webhooks are signature-verified before anything is processed.
Operational hygiene
Immutable container builds, migrations run as reviewed jobs, secrets in the cluster not in code, rate limiting on public endpoints, and structured error monitoring.
UK GDPR ready
Cookie consent, a plain-English privacy policy, DPA on request, and tooling to export or erase a visitor's conversations when they ask.
Common security questions
OpenAI, Anthropic and Google, via their enterprise APIs. You choose the model per agent. Prompts and content are sent only to the provider of the model you selected.
Yes. Allow-list domains per agent; requests from any other origin are rejected.
Yes. Email hello@supportai.co.uk and we'll send our DPA and answer your questionnaire.
Delete the conversation from the inbox or via the API; leads, messages and analytics rows tied to it are removed.
Need the paperwork?
We're happy to complete vendor questionnaires and sign a DPA before you commit.