Security First
Built for Trust.
botts.ai is engineered with a Zero-Trust architecture, hosted in Switzerland, and is GDPR compliant.
*** ***
Account Security
Two-Factor Authentication (2FA) and phishing-resistant Passkeys (WebAuthn).
Encryption
TLS 1.3 in transit. Credentials, secrets, and stored data encrypted at rest.
Zero Trust Access
Admin access is secured via Tailscale (VPN) with no public ports exposed.
Swiss Hosting
Infrastructure in Switzerland, with option for global LLM models.
Your dataModel training
Your data never trains AI
Your conversations and knowledge are never used to train any model.
Compliance & Privacy
We rigorously adhere to Swiss nDSG, EU GDPR, and the EU AI Act.
- Swiss Data Residency (nFADP)
- No training on your data
- All subprocessors disclosed publicly
- Right to access, export, and delete
- You own your data — we are only a processor
Our Subprocessors
- Infomaniak (Switzerland) — Hosting, database, file storage, and Swiss-hosted AI inference
- Microsoft Azure (Switzerland — Zurich region) — Azure OpenAI for text and voice models
- Twilio (USA) — Phone number provisioning and voice call routing
- Stripe (Ireland / USA) — Payment processing for subscriptions and credits
- Lettermint (Netherlands / EU) — Transactional email (verification, password reset, invites)
- Modal Labs (USA) — Hosted web-crawling infrastructure for knowledge ingestion
Frequently Asked Questions
Is botts.ai GDPR compliant?
Do you use my data to train AI models?
Will model providers (OpenAI, Anthropic, Google, etc.) use my data to train their models?
Can data be permanently deleted?
Who owns my data?
BOTTS.AI