Trust
Security at ChatRobo
What is actually in place today, and — just as importantly — what isn't yet. ChatRobo is early, and a security page that overstates is worse than one that is short.
How we protect your data
Encryption in transit and at rest
Traffic is served over TLS. Data sits in managed Postgres, which encrypts at rest. Credentials live in environment configuration, never in the codebase.
Tenant isolation
Every assistant belongs to a tenant, and every read and write is scoped by that tenant id on the server — not in the browser. Ownership is re-checked on each request rather than trusted from the session.
Domain allow-lists
You choose which domains may embed each assistant. The check runs server-side on the answer endpoint, so it cannot be bypassed by editing the page that hosts the widget.
Scoped API access
API clients are granted individual scopes — reads are not implicit — and every call is written to an audit log.
Abuse and cost limits
Per-assistant and per-IP rate limits, monthly message quotas, and per-turn ceilings on model rounds and spend, so a runaway or hostile conversation is stopped rather than absorbed.
Model providers
We send a model only the passages needed to answer the turn. Our provider's API terms state that API content is not used to train their models; we rely on those terms rather than a bespoke agreement.
Practices
- Data minimisation — conversation telemetry stores hashes and redacted, truncated previews rather than raw arguments, and visitor IP addresses are salted-hashed, never stored in the clear.
- Dependencies are updated regularly and scanned by our hosting provider's tooling.
- Managed hosting and managed Postgres, with the provider's automated backups.
Not in place yet
We would rather you learn this here than during a vendor review.
- No third-party audit or certification. We hold no SOC 2, ISO 27001 or equivalent attestation, and no audit is currently underway.
- No automated uptime or security monitoring. There is no alerting pipeline today. Our status page is maintained by hand and says so.
- No formal incident-response programme. We have not documented severities, timelines or a tested recovery runbook.
- No SSO or MFA-gated production access process beyond the access controls of our hosting and database providers.
- No penetration test has been carried out.
If your procurement process requires any of the above, tell us — it helps us prioritise, and we would rather be told no now than discovered later.
Report a vulnerability
We welcome reports from security researchers. If you believe you've found a vulnerability, email security@chatrobo.appwith details and reproduction steps. Please give us a reasonable window to remediate before public disclosure; we won't pursue good-faith research that respects our users' privacy and data.
For data-processing terms and sub-processors, see our Compliance page and Privacy Policy.
Have a security or vendor-review question?
Our team is happy to walk through controls, complete questionnaires, and share documentation.