Enterprise Trust & Security

Security at BolixAI

Defending your customer interactions with end-to-end encryption, strict tenant isolation, and enterprise governance.

Zero Public Model TrainingAES-256 & TLS 1.3
TLS 1.3 & AES-256
End-to-end encryption
Row-Level Security
Hard tenant isolation
Zero Model Training
Private embeddings
GDPR & SOC 2 Ready
Enterprise governance
99.9% SLA Target
High availability
Core Architectural Controls

Six Pillars of BolixAI Defense

Engineered from the ground up for mission-critical customer conversations.

Cryptographic Protection

  • Enforced TLS 1.3 with Perfect Forward Secrecy across all web, API, and webhook traffic
  • AES-256 database-level and storage encryption at rest across all disks and vector embeddings
  • End-to-end encrypted bi-directional audio streaming for all voice support calls
  • Secure key rotation with hardware security module (HSM) managed secrets
  • Automated PII tokenization and scrubbing prior to long-term logging

Infrastructure & Isolation

  • Hard tenant isolation enforced via PostgreSQL Row-Level Security (RLS)
  • Multi-region cloud infrastructure with 99.9% uptime target and automated failover
  • Dedicated Redis clusters with TLS encryption and isolated access tokens
  • Zero standing access policy — infrastructure changes require just-in-time approval
  • Automated daily encrypted snapshot backups with 30-day geographic retention

Access Governance & RBAC

  • Mandatory Multi-Factor Authentication (MFA) across all administrative consoles
  • Granular Role-Based Access Control (RBAC) within organizational workspaces
  • Short-lived session tokens with automated revocation and continuous authorization
  • Immutable audit logging capturing every prompt change, API request, and export
  • Strict separation of production, staging, and sandboxed test environments

Application Defense & OWASP

  • Comprehensive OWASP Top 10 mitigations implemented across all API endpoints
  • Strict CSRF protection, Content Security Policies (CSP), and parameterized queries
  • Adaptive rate-limiting and DDoS mitigation filtering anomalous burst traffic
  • Automated static and dynamic dependency vulnerability scans on every code build
  • Real-time prompt injection filtering and guardrail verification on LLM outputs

AI Governance & Privacy

  • Zero Model Training: Your private data is NEVER used to train public foundational AI models
  • Dynamic in-memory inference without persistent prompt leakage across workspaces
  • Configurable PII redaction rules for phone numbers, payment tokens, and IDs
  • Deterministic safety guardrails preventing hallucinated or off-policy agent responses
  • Customer-owned knowledge base vector boundaries isolated per organization

Compliance & Governance

  • GDPR-aligned Data Processing Addendums (DPA) with Standard Contractual Clauses
  • SOC 2 Type II aligned internal control framework and audit trail logging
  • PCI-DSS Level 1 compliance via certified payment gateways (Stripe & Razorpay)
  • Meta WhatsApp Business Policy and telecom regulatory compliance
  • Annual third-party penetration testing and vulnerability assessments
Security FAQ

Frequently Asked Security Questions

Does BolixAI train AI foundation models on our proprietary business data?

No. BolixAI maintains a strict zero-model-training policy. Your uploaded PDF documents, knowledge bases, customer WhatsApp transcripts, and call audio are never used to train public machine learning models. Your agents query private embeddings isolated strictly to your organization.

How is tenant isolation maintained in multi-tenant environments?

We enforce logical tenant isolation at the database layer using PostgreSQL Row-Level Security (RLS) and encrypted vector namespaces. Every database query, vector search, and API request is authenticated and bounded strictly to the caller's tenant ID.

Can BolixAI employees view our customer conversations?

Employee access to production data is strictly prohibited by default. In rare cases where support requires debugging, access is granted temporarily under a just-in-time authorization model with MFA, and all access events are recorded in immutable audit logs.

How are voice call transcripts and audio recordings protected?

Voice audio streams are encrypted in transit using SRTP / TLS 1.3 and stored at rest using AES-256. Automated PII scrubbing can be activated to mask sensitive customer numbers and names. You retain full controls to export or purge call records at any time.

What is your disaster recovery and backup strategy?

We take daily automated encrypted snapshots stored in geo-redundant storage with a 30-day retention window. Our Recovery Time Objective (RTO) target is under 4 hours and Recovery Point Objective (RPO) is under 1 hour for critical database state.

How can our security team review your Data Processing Addendum (DPA)?

We provide standard enterprise DPAs with Standard Contractual Clauses (SCCs) for European, Indian, and global deployments. Reach out to privacy@bolixai.com to request our pre-signed compliance package.

Responsible Disclosure Policy

We value the contributions of ethical security researchers. If you identify a potential security vulnerability within the BolixAI platform, please disclose it responsibly so we can remediate it promptly:

Report vulnerabilities privately to security@bolixai.com with reproducible steps
Do not access, modify, or exfiltrate another customer's tenant data during research
We commit to acknowledging verified reports within twenty-four (24) business hours
We will provide ongoing status updates and coordinate safe disclosure timing
🔒 Report to: security@bolixai.com

Need a Custom Security Review?

Our security engineering team assists enterprise customers with vendor risk assessments, SOC 2 compliance documentation, and custom architectural questionnaires.

Request Security Review Privacy Policy