Security & trust

Security at IotaBot

How we protect your workspace, your customers’ data and your connected channels — each point below describes how the product works today.

Access control

  • Role-based access with five roles: owner, admin, supervisor, agent and viewer.
  • A separate developer role that can manage API keys and webhooks and nothing else.
  • Per-member scoping to specific websites, Instagram accounts and mailboxes — access is denied by default.
  • Named feature grants, such as Marketing, given per team member independently of role.
  • Optional four-eyes approval: a second team member must approve a campaign before it sends.
  • Passwordless sign-in with a one-time email code or Google — there are no passwords to leak.

Data protection

  • Every workspace’s content, conversations and contacts are isolated per tenant.
  • Access tokens for connected channels (WhatsApp, Instagram, stores) are encrypted at rest with AES-256-GCM.
  • API keys are stored only as hashes; the full key is shown once, at creation.
  • Visitor identity for logged-in users is verified with a server-side HMAC signature, never trusted from the browser.
  • Store orders are shown only to a shopper whose identity is verified server-side — never on an order number or email typed into chat.
  • IotaBot staff access to a workspace for support is time-limited to 30 minutes and recorded in the audit log.

API and webhook security

  • Separate test and live API keys; test keys run every check and never send a real message.
  • Per-key IP allowlisting.
  • Alerts when an API key is used from a network it has not been used from before.
  • Keys can be rolled or revoked at any time.
  • Every webhook is signed with HMAC-SHA256 over a timestamp and the body, so your server can verify it and reject replays.
  • Webhooks are sent from published static IP addresses you can allowlist.
  • An owner-visible audit log of API key and webhook changes, exportable as CSV, plus a log of API requests.

AI safety and control

  • The assistant answers from your own knowledge base and says so when it does not know, rather than guessing.
  • Plain-English bot rules: access rules (for example an age check) are enforced in code before the AI runs; guidelines shape its tone and scope.
  • Knowledge sources and tools protected by an access rule are withheld from the AI until the visitor passes the check.
  • Every rule check is recorded.
  • The AI model is a setting, chosen per channel, not a hidden dependency.
  • A person can take over any conversation at any moment, and the AI stays quiet while they do.

Privacy and compliance

  • A Data Processing Agreement that a workspace owner or admin can review and accept in the dashboard, with a signed copy available to download.
  • GDPR consent as a built-in form field type.
  • Marketing opt-outs are tracked per contact and channel and honoured automatically by every campaign.
  • Every marketing email carries an unsubscribe link.
  • Outbound email is sent from your own verified domain with SPF and DKIM.
  • WhatsApp and Instagram connect only through Meta’s official APIs, and Meta’s 24-hour messaging window is enforced, not worked around.

Reliability and transparency

  • A public status page for the platform and its channels.
  • Outbound messages go through a paced, visible sending queue — what is waiting, sent and failed is shown, not hidden.
  • Meta’s 200-per-hour Instagram send cap is respected by queuing, never by dropping messages.
  • Every ticket assignment, status change and SLA breach is recorded on the ticket’s timeline.
FAQ

Security questions

Who can see my customers’ conversations?

Only members of your workspace, limited by their role and by the websites, Instagram accounts and mailboxes they have been given. IotaBot staff can enter a workspace only for support, for at most 30 minutes at a time, and each visit is logged.

Is there a Data Processing Agreement?

Yes. A workspace owner or admin can review and accept IotaBot’s DPA in the dashboard and download a signed copy.

How are connected account tokens stored?

Encrypted at rest with AES-256-GCM. API keys are stored only as hashes.

Can I restrict API access to my servers?

Yes. Each API key can carry an IP allowlist, and you are alerted when a key is used from a new network.

How do I verify a webhook really came from IotaBot?

Each delivery is signed with HMAC-SHA256 over a timestamp and the raw body using your endpoint’s secret. Verify the signature and reject old timestamps to block replays.

Can I get answers to a security questionnaire?

Yes — contact us with your questionnaire and we will answer it directly.