Security

Agents you can put in production. Controls you can show your auditor.

The documents flowing through Botminds are loan files, contracts, financial statements, and claims — so security is not a feature, it is the operating assumption. Here is how the platform is secured, by category, in the language your security review uses.

AI & Agentic security

Autonomy inside guardrails

Agents on Botminds act inside explicit policy, with people at the decision points.

  • Policy-bounded autonomy. Every agent runs with an explicit scope — the collections it can read, the actions it can take, the tools it can call. Nothing is implied.
  • Human-in-the-loop approval gates. Consequential steps route to a person: reviews and approvals are first-class workflow stages, not bolt-ons.
  • Guardrails on inputs and outputs. Outputs are documented, reviewable, and cited to their source — every number traceable to the page it came from.
  • Evaluations before and after deployment. Agent behavior is tested against expected outcomes before go-live and monitored after, so drift is caught, not discovered.
  • Model governance. Which model runs where is a controlled, auditable configuration choice — including Azure OpenAI for Azure-committed enterprises.
  • No training on customer data. Your inputs and outputs are not used to train models. Your data works for you, not for the platform.

Data security

Your data stays yours

Encrypted everywhere, isolated per tenant, and gone when you say so.

  • Encryption in transit and at rest. TLS on the wire, AES-256 at rest — all data, all the time.
  • Tenant isolation. Each customer's collections, indexes, and agent workspaces are isolated; one tenant's data never serves another's queries.
  • Retention and deletion. Data is kept only as long as the workflow needs it; deletion requests remove it from the platform, verifiably.
  • Data portability. Documents, extracted data, and decisions are exportable — adopting the platform never means losing access to your own records.
  • Deployment on your terms. Multi-tenant SaaS, dedicated cloud, or on-premises — the same controls, wherever your policy requires the data to live.

Platform security

Zero-trust by default

Identity-first access, permissions to the collection level, and a log that never forgets.

  • SSO and SAML. Sign-in through your identity provider, with MFA and OAuth-based authentication layered on.
  • RBAC to the collection level. Role-based access control decides who can see, modify, or manage each collection, workflow, and dataset — not just each app.
  • Immutable audit logging. Every action on the platform — human or agent — lands in an audit log that cannot be altered. Full traceability for every AI-assisted decision.
  • Observability. Agent runs, data flows, and system health are monitored continuously, so anomalies surface as alerts, not incidents.
  • Regular security testing. The platform undergoes recurring security audits and penetration testing.

Compliance

Evidence, not assertions

The certifications your procurement checklist asks for — audit reports available on request.

SOC 2 Type II

SOC 2 Type II

Independently audited controls over how customer data is handled, continuously.

ISO 27001

ISO 27001

Information security managed to the international standard.

GDPR

GDPR

Privacy by design and by default, with data residency controls for regional requirements.

Talk to security

Security questionnaire, audit reports, or an architecture walkthrough — bring your review, we’ll bring the evidence.

Talk to security