Security & trust

Your customers' conversations deserve real protection

Security is a set of defaults, not a checkbox. This is how SupportAi is built and run.

Encryption everywhere

TLS 1.2+ on every connection. Databases and object storage encrypted at rest. API keys and channel tokens are hashed or stored encrypted and never shown twice.

Workspace access control

Owner, admin, agent and viewer roles. Invitations expire, memberships are auditable, and API keys are scoped (read / write / chat) and revocable instantly.

AI guardrails

Prompt-injection detection, blocked topics, system-prompt leak checks and a configurable fallback answer. Custom actions only ever call the endpoints you define.

Your data trains your agent only

Content you upload is used solely to answer your customers. We do not train foundation models on your data, and model providers are used under their zero-retention API terms.

Data residency & retention

Hosted in the UK/EU on our Kubernetes cluster. Delete a bot and its sources, embeddings and conversations go with it; delete your account and everything is purged.

Signed integrations

Outbound webhooks are HMAC-SHA256 signed with per-endpoint secrets. Inbound Slack, WhatsApp and email webhooks are signature-verified before anything is processed.

Operational hygiene

Immutable container builds, migrations run as reviewed jobs, secrets in the cluster not in code, rate limiting on public endpoints, and structured error monitoring.

UK GDPR ready

Cookie consent, a plain-English privacy policy, DPA on request, and tooling to export or erase a visitor's conversations when they ask.

Questions

Common security questions

Which AI providers do you use?

OpenAI, Anthropic and Google, via their enterprise APIs. You choose the model per agent. Prompts and content are sent only to the provider of the model you selected.

Can I restrict where my widget loads?

Yes. Allow-list domains per agent; requests from any other origin are rejected.

Do you offer a DPA or security questionnaire?

Yes. Email hello@supportai.co.uk and we'll send our DPA and answer your questionnaire.

How do I delete a visitor's data?

Delete the conversation from the inbox or via the API; leads, messages and analytics rows tied to it are removed.

Need the paperwork?

We're happy to complete vendor questionnaires and sign a DPA before you commit.

Security & trust | SupportAi