BotNira Trust Center Visit BotNira.com โ†’
BOTNIRA SECURITY

Security built around protecting your data.

BotNira is designed with security controls covering data transmission, storage, access, infrastructure, monitoring, vulnerability management and incident response.

SECURITY PROGRAM
โœ“
Security Controls Active

Multiple layers of protection across the BotNira platform.

Encryption Enabled
2FA Supported
Vulnerability scanning Regular
Penetration testing Completed

Security is part of the platform, not an afterthought.

BotNira handles business and customer communication data across voice calls, WhatsApp, email, website chat and other supported workflows.

Our security program is designed to protect this information throughout its lifecycle โ€” from transmission and authentication through storage, processing, monitoring and deletion.

Security controls are combined with regional data-residency architecture so that customer data is stored according to the applicable BotNira regional environment.

Multiple layers of security

BotNira uses multiple technical and organizational controls rather than relying on a single security mechanism.

๐Ÿ”’ Encryption

Data is protected through encryption controls both while being transmitted and while stored.

๐Ÿ›ก๏ธ Network Protection

Firewall and DDoS protection help defend BotNira infrastructure against unauthorized and malicious network traffic.

๐Ÿ”‘ Authentication

Two-factor authentication provides an additional layer of protection for supported account access.

๐Ÿ” Vulnerability Management

Regular vulnerability scanning is performed to identify potential weaknesses.

๐Ÿงช Penetration Testing

Penetration testing has been completed as part of the BotNira security program.

๐Ÿšจ Incident Response

A dedicated security team is responsible for responding to security incidents.

Security controls protecting BotNira

The following controls form the core of BotNira's technical security architecture.

ACTIVE

SSL / TLS

Secure TLS connections are used to protect information transmitted between users, applications and BotNira services.

ACTIVE

Encryption at Rest

Stored information is protected using encryption controls designed to reduce the risk of unauthorized access.

ACTIVE

Encryption in Transit

Information transmitted across supported communication channels is protected through encrypted connections.

ACTIVE

Two-Factor Authentication

2FA provides an additional authentication factor to help protect supported BotNira accounts.

ACTIVE

Firewall Protection

Network firewall controls help restrict unauthorized network traffic and protect infrastructure.

ACTIVE

DDoS Protection

DDoS protection helps mitigate malicious traffic designed to overwhelm services.

ACTIVE

Database Backups

Regular database backups support resilience, recovery and protection against data loss.

REGULAR

Vulnerability Scanning

BotNira performs regular vulnerability scanning to identify potential security weaknesses.

COMPLETED

Penetration Testing

Penetration testing has been completed to evaluate security defenses and identify potential weaknesses.

RESTRICTED

Internal Data Access

Customer data is not accessible to members of the BotNira team as part of ordinary operational activities.

ACTIVE

Security Team

A dedicated security team is responsible for security monitoring and incident response.

CONTROLLED

Data Deletion

Following account closure, applicable data is retained for up to 45 days and then permanently deleted according to BotNira's retention policy.

Access to customer data is restricted.

BotNira follows a restricted-access approach for customer information.

Members of the BotNira team do not have ordinary access to customer data as part of their normal day-to-day operations.

This reduces the number of people who can interact with customer information and forms part of BotNira's overall security architecture.

Principle: Customer data should only be accessible through authorized systems and processes required to provide or secure the service.

Security across the data lifecycle

01
STAGE

Transmission

Data transmitted between supported systems is protected through encrypted connections.

02
STAGE

Processing

BotNira processes information through its application and applicable integrated providers required to deliver specific functionality.

03
STAGE

Storage

Customer data is stored within the appropriate BotNira regional environment based on the vendor's region.

04
STAGE

Backup

Regular backups support service resilience and recovery. Regional data-residency commitments apply to applicable vendor data.

05
STAGE

Monitoring

Security monitoring and vulnerability management help identify potential security issues.

06
STAGE

Deletion

Following account closure, applicable data is retained for up to 45 days before permanent deletion.

Regional storage is part of our security model.

BotNira operates regional environments so that vendor data is stored according to its applicable geographic region.

๐Ÿ‡จ๐Ÿ‡ฆ Canada

Canadian vendor data is stored and backed up within the Canadian regional environment.

View Canada โ†’

๐Ÿ‡บ๐Ÿ‡ธ United States

U.S. vendor data is stored and backed up within the U.S. regional environment.

View United States โ†’

๐Ÿ‡ช๐Ÿ‡บ Europe

European vendor data is stored and backed up within the European regional environment.

View Europe โ†’

๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom

UK vendor data is stored and backed up within the UK regional environment.

View United Kingdom โ†’

๐Ÿ‡ฆ๐Ÿ‡บ Australia

Australian vendor data is stored and backed up within the Australian regional environment.

View Australia โ†’

๐Ÿ‡ฎ๐Ÿ‡ณ India

Indian vendor data is stored and backed up within the Indian regional environment.

View India โ†’

Testing and continuous security improvement

Security is an ongoing process. BotNira performs regular vulnerability scanning and has completed penetration testing as part of its security program.

Findings from security activities can be used to identify areas for remediation and improve the overall security posture of the platform.

COMPLETED

Penetration Test

A penetration testing assessment has been completed.

View certificate โ†’

Independent security and compliance evidence

BotNira maintains the following certificates and assessment documentation as part of its broader security and compliance program.

BotNira ISO 27001 certificate

ISO/IEC 27001

Information security management.

View certificate โ†’
BotNira ISO 27701 certificate

ISO/IEC 27701

Privacy information management.

View certificate โ†’
BotNira SOC 2 Type II certificate

SOC 2 Type II

Service organization controls and assurance.

View certificate โ†’
BotNira GDPR compliance certificate

GDPR Compliance

Privacy and data protection framework.

View certificate โ†’
BotNira HIPAA certificate

HIPAA

Security and privacy controls for applicable healthcare use cases.

View certificate โ†’
BotNira penetration testing certificate

Penetration Testing

Security assessment and penetration testing.

View certificate โ†’
Certification note: These certificates and assessments form part of BotNira's security and compliance documentation. Customers should review the scope, validity period and applicable terms of each individual document for their particular requirements.

HIPAA documentation

BotNira maintains HIPAA-related certification documentation as part of its security program.

However, a certificate alone does not mean that every BotNira customer automatically has a HIPAA-covered arrangement.

At present, BotNira does not represent that it has entered into a Business Associate Agreement (BAA) with every customer. Healthcare customers with HIPAA requirements should contact BotNira before using the service for regulated PHI.

Important: The HIPAA Security Rule requires covered entities and business associates to implement appropriate administrative, physical and technical safeguards for electronic protected health information. :contentReference[oaicite:2]{index=2}

Responding to security incidents

BotNira maintains a security response process for identifying, investigating and responding to security incidents.

01

Detection

Security monitoring and vulnerability-management activities can help identify potential security issues.

02

Investigation

Reported or identified security events can be investigated by the security team.

03

Containment

Appropriate technical and operational measures may be taken to contain identified threats.

04

Remediation

Identified security issues are addressed through appropriate corrective actions.

Security includes responsible deletion.

BotNira does not retain customer data indefinitely after an account is closed.

When a vendor stops using BotNira and closes its account, applicable data is retained for 45 days .

After the applicable 45-day period, the data is permanently deleted according to BotNira's retention process.

While an account remains active, vendors can manage and delete their customer calls, messages and related data using available BotNira functionality.

Know who is involved in your data flow.

BotNira provides transparency about third-party providers involved in communication and AI functionality.

Twilio

Provides telephone connectivity and acts as the communication bridge for applicable voice services.

Meta / WhatsApp

Provides WhatsApp communication infrastructure for applicable messaging services.

OpenAI

Provides AI services used for applicable BotNira AI-powered processing.

Security documentation

Additional security and compliance information is available throughout the BotNira Trust Center.

Data Residency

Understand where BotNira stores vendor and customer data by region.

View Data Residency โ†’

Privacy

Learn how BotNira collects, uses, retains and protects personal information.

View Privacy โ†’

AI Security

Understand BotNira's AI architecture and OpenAI processing.

View AI Security โ†’

Subprocessors

Review third-party providers used to provide BotNira functionality.

View Subprocessors โ†’
@

Have a security concern?

Security-related questions or concerns can be directed to the BotNira security team.

security@botnira.com

Frequently asked security questions

Does BotNira encrypt data?
Yes. BotNira uses encryption controls for information in transit and stored information.
Does BotNira use two-factor authentication?
Yes. Two-factor authentication is supported as an additional account security control.
Does BotNira perform penetration testing?
Yes. BotNira has completed penetration testing and maintains related assessment documentation.
Does BotNira regularly scan for vulnerabilities?
Yes. Regular vulnerability scanning is part of the BotNira security program.
Can BotNira employees access my customer data?
Customer data is not accessible to BotNira team members as part of ordinary operational activities.
How long does BotNira retain data after account closure?
Applicable data is retained for up to 45 days after account closure and then permanently deleted.
Where is my data stored?
BotNira uses regional infrastructure. Vendor data is stored and backed up in the applicable regional environment.
Does BotNira use third-party providers?
Yes. Depending on the service used, providers such as Twilio, Meta/WhatsApp and OpenAI may participate in specific communication or AI processing functions.
Does having a HIPAA certificate mean I can automatically use BotNira for PHI?
No. Healthcare customers should contact BotNira before processing regulated PHI. A HIPAA-related certificate does not by itself create a Business Associate Agreement or establish that every customer configuration satisfies HIPAA.
How can I contact BotNira about security?
Security information: The information on this page describes BotNira's current security controls and security program for transparency purposes. It does not constitute legal advice, a warranty, or a representation that a customer's particular use of BotNira satisfies every regulatory, contractual or industry-specific requirement applicable to that customer.

Certifications and assessments should be reviewed according to their individual scope, validity period and applicable terms.

Security, transparency and control.

Explore BotNira's regional data residency, subprocessors, AI processing and privacy documentation.

Have a security or compliance question?

Our team can help with security documentation, compliance information, data residency questions, enterprise reviews and security questionnaires.