Compliance built for trust.
Explore BotNira's compliance certifications, security assessments, privacy practices, regional data residency and legal resources.
Our compliance program is designed to help customers, security teams, procurement teams and legal teams evaluate BotNira with confidence.
Security, privacy and regulatory resources.
Security and compliance are part of the BotNira platform.
BotNira provides AI-powered communication services for businesses that may process customer conversations, contact information, messages, calls and other business data.
Our security and compliance program focuses on protecting information throughout its lifecycle, including transmission, processing, storage, access and deletion.
We maintain technical and organizational controls designed to support security, privacy and data protection requirements across the regions where BotNira operates.
Our compliance documentation.
BotNira maintains certification and assessment documentation supporting its security and privacy program.
GDPR
GDPR-related compliance documentation supporting BotNira's privacy and data protection program.
View Certificate →HIPAA
BotNira maintains HIPAA-related certification documentation for applicable healthcare requirements.
Specific healthcare implementations may require additional contractual and technical arrangements.
View Certificate →ISO 27701
Privacy information management certification documentation supporting BotNira's privacy program.
View Certificate →ISO 27001
Information security management certification documentation supporting BotNira's security management program.
View Certificate →SOC 2 Type II
SOC 2 Type II documentation supporting controls relevant to security and operational trust.
View Certificate →Penetration Testing
Documentation relating to completed penetration testing activities as part of BotNira's security program.
View Assessment →Protection across the data lifecycle.
BotNira uses technical and organizational safeguards to protect customer and vendor data.
SSL / TLS
Secure communication channels protect information transmitted between systems.
Encryption at Rest
Stored information is protected using encryption controls.
Encryption in Transit
Data transmitted between systems is protected using encrypted communication.
Two-Factor Authentication
Additional authentication controls help protect account access.
Firewall Protection
Network security controls help protect BotNira infrastructure.
DDoS Protection
Infrastructure includes protection designed to mitigate distributed denial-of-service attacks.
Regular Backups
Data is backed up as part of BotNira's infrastructure and recovery practices.
Vulnerability Scanning
BotNira performs regular vulnerability scanning as part of its security program.
Penetration Testing
Penetration testing has been completed as part of the security assessment program.
Access Controls
Access to customer data is restricted through organizational and technical access controls.
Incident Response
A dedicated security function supports incident detection, investigation and response.
Data Deletion
Applicable data is permanently deleted following the defined account closure retention period.
Regional data storage.
BotNira provides regional storage and backup environments for supported markets.
Canada
Canadian vendor and applicable customer data is stored and backed up in the designated Canadian environment.
Canada Data Residency →United States
US vendor and applicable customer data is stored and backed up in the designated US environment.
US Data Residency →European Union
European vendor and applicable customer data is stored and backed up in the designated European environment.
EU Data Residency →United Kingdom
UK vendor and applicable customer data is stored and backed up in the designated UK environment.
UK Data Residency →Australia
Australian vendor and applicable customer data is stored and backed up in the designated Australian environment.
Australia Data Residency →India
Indian vendor and applicable customer data is stored and backed up in the designated Indian environment.
India Data Residency →Transparency about AI processing.
BotNira uses OpenAI API and business services for applicable AI and speech processing.
Because of this architecture, certain AI processing can take place in the United States even when a vendor's primary BotNira data storage environment is located in another region.
Regional storage and backup residency should therefore be understood separately from third-party AI processing.
View AI Processing Documentation →How data moves through BotNira.
Different communication channels can involve different infrastructure providers.
Voice Calls
Phone call → Twilio → BotNira → OpenAI speech/AI processing → BotNira → CRM/integration → storage.
WhatsApp communication involves Meta's infrastructure for message transmission. Applicable processing and storage are then handled through BotNira.
Email communication is handled through BotNira according to the applicable service configuration.
Website Chat
Website chat is handled through BotNira's platform without an additional communication intermediary.
Retention and deletion.
BotNira retains applicable vendor data while the vendor continues to use the service.
When a vendor closes their BotNira account, applicable data is retained for 45 days.
Following this retention period, applicable data is permanently deleted, subject to any applicable legal or contractual requirements.
While actively using BotNira, vendors can manage and delete applicable customer calls, messages and other data according to available platform functionality.
View Privacy Policy →Transparency about subprocessors.
Some BotNira functionality depends on external infrastructure and technology providers.
Twilio
Telecommunications infrastructure for applicable phone communications.
OpenAI
AI and speech processing for applicable BotNira functionality.
Meta
WhatsApp infrastructure involved in applicable WhatsApp communications.
HIPAA certification and healthcare use.
BotNira maintains HIPAA-related certification documentation.
However, BotNira is currently not signing additional HIPAA agreements with customers. The existence of a HIPAA-related certification does not by itself mean that every BotNira implementation is suitable for every regulated healthcare use case.
Customers should evaluate their specific regulatory, contractual and technical requirements before using BotNira for regulated healthcare information.
View HIPAA Documentation →Our compliance program is continuously evolving.
BotNira is continuing to develop and strengthen its legal, privacy, security and compliance documentation across the jurisdictions in which its services are offered.
Additional jurisdiction-specific agreements, policies, assessments and documentation are being developed as part of this program.
Our goal is to establish a comprehensive compliance framework that supports customers across industries and regions.
View Legal Center →Explore the Trust Center.
Find additional information for security, privacy, legal and compliance reviews.
Need additional documentation?
Customers and prospective customers may contact BotNira for additional security, privacy, compliance or procurement documentation.
Please include the specific compliance requirement, questionnaire or documentation request when contacting our team.
Kamal@botnira.comSecurity. Privacy. Transparency.
Explore BotNira's complete security, privacy, compliance and data-residency documentation.