← BuddyAI
Security
How BuddyAI protects your data and your users' data. Questions or a security review? Email hello@getbuddyai.com.
Tenant isolation
- Every workspace's data is scoped to that workspace on the server and enforced again by database row-level security.
- The in-product widget never talks to the database directly. It uses a narrow API that accepts only the operations the widget needs.
- Deployment tokens identify a workspace and can be revoked at any time.
What the widget collects
- Clicks, page views, and the JavaScript errors and failed requests users hit, tied to the page and the action just before.
- No request or response bodies or headers. URLs are reduced to paths, and emails, tokens and long numbers are redacted from error messages.
- Optional: user email and name, if your app provides them. Provide a server-side signature to verify them.
Identity verification
- Your server signs each user's email with a per-workspace secret (HMAC-SHA256). Without a valid signature, visitors are treated as anonymous and can't read another person's conversation history.
Access control and billing
- Dashboard access requires sign-in and workspace membership. Billing and membership changes happen only on our servers.
- Payments are handled by Dodo Payments. We never see or store card details.
AI processing
- Buddy's answers are generated by third-party AI providers. We send only what's needed to answer (the question, relevant docs and tour context).
- Autopilot actions are shown to the user and require confirmation for anything that changes data.
Infrastructure
- Hosted on AWS (Amplify) with data in Supabase (Postgres). Traffic is encrypted in transit.
- Webhooks are signature-verified and expensive endpoints are rate limited.
To report a vulnerability, email hello@getbuddyai.com. See also our privacy policy.