Security First

Built for Trust.

botts.ai is engineered with a Zero-Trust architecture, hosted in Switzerland, and is GDPR compliant.

*** ***

Account Security

Two-Factor Authentication (2FA) and phishing-resistant Passkeys (WebAuthn).

Encryption

TLS 1.3 in transit. Credentials, secrets, and stored data encrypted at rest.

Zero Trust Access

Admin access is secured via Tailscale (VPN) with no public ports exposed.

Swiss Hosting

Infrastructure in Switzerland, with option for global LLM models.

Your dataModel training

Your data never trains AI

Your conversations and knowledge are never used to train any model.

Compliance & Privacy

We rigorously adhere to Swiss nDSG, EU GDPR, and the EU AI Act.

  • Swiss Data Residency (nFADP)
  • No training on your data
  • All subprocessors disclosed publicly
  • Right to access, export, and delete
  • You own your data — we are only a processor

Our Subprocessors

  • Infomaniak (Switzerland) — Hosting, database, file storage, and Swiss-hosted AI inference
  • Microsoft Azure (Switzerland — Zurich region) — Azure OpenAI for text and voice models
  • Twilio (USA) — Phone number provisioning and voice call routing
  • Stripe (Ireland / USA) — Payment processing for subscriptions and credits
  • Lettermint (Netherlands / EU) — Transactional email (verification, password reset, invites)
  • Modal Labs (USA) — Hosted web-crawling infrastructure for knowledge ingestion

Frequently Asked Questions

Is botts.ai GDPR compliant?

Do you use my data to train AI models?

Will model providers (OpenAI, Anthropic, Google, etc.) use my data to train their models?

Can data be permanently deleted?

Who owns my data?

BOTTS.AI