Transparency
Security and data handling at Botnea
A transparent overview of how Botnea handles workspace access, company data, and AI-provider interactions.
This page only describes things we can point to as evidence. Where we cannot, we say so instead of filling the gap with reassuring language.
Independent certifications
Botnea is not currently SOC 2 or ISO 27001 certified, and we are not presenting any equivalent independent audit. We describe the controls that are actually implemented so customers can evaluate the product based on evidence rather than labels.
We do not hold a completed security questionnaire, penetration-test report, audit package, uptime SLA, or standard data processing agreement to hand out today. If your procurement process requires any of these, tell us what you need and we will answer in writing what exists and what does not.
Send a security or data-handling question — it reaches us at sales@botnea.com. We do not yet operate a separate, monitored security mailbox, so please use this address.
Architecture and access to a workspace
Botnea is a hosted web application at app.botnea.com. Reaching a workspace requires signing in through that application; there is no anonymous entry point to workspace content.
Beyond that, we are deliberately not publishing statements about tenant isolation, database-level authorization, or server-side permission enforcement. Those claims require configuration evidence we are not able to show you on a public page, and we are not willing to imply safety from a technology name alone. We will discuss the architecture directly with a prospective customer’s technical reviewer.
How data flows
1. A member types or uploads something
The content is whatever your team chooses to put into the workspace. Botnea does not filter it for you before it leaves your browser.
2. Botnea receives the request
The request is handled by the Botnea application at app.botnea.com and associated with the signed-in member and their workspace.
3. The selected AI provider processes it
To produce an answer, the content of the request is sent to the AI provider behind the selected model. That provider's own terms and data-handling policy apply to that step. We are not publishing a provider-by-provider list until we can publish the exact configuration behind it.
4. The response returns to the workspace
The answer is returned to the member who asked for it.
5. Storage and retention
We are not publishing retention periods, deletion timelines, or backup behaviour, because we cannot evidence specific numbers here. Treat retention as undocumented rather than as "none" and ask us before putting regulated or highly sensitive data into a workspace.
Whether an AI provider trains on content sent to it depends on that provider and on the account configuration used. We do not claim a training exclusion.
Access and administration
Administrative capabilities such as who can use which model, what usage is visible, and what company knowledge is shared are product features. We describe them on the homepage as functionality, not as security guarantees, and we are not restating them here as controls until we can publish evidence of how they are enforced.
Encryption and infrastructure
Traffic to this website and to app.botnea.com is served over HTTPS. We are not publishing claims about encryption at rest, key management, hosting regions, or data residency, because those depend on hosting and database configuration we are not presenting publicly. We are also not going to attribute someone else’s certification to Botnea: a platform’s compliance status is theirs, not ours.
Subprocessors and AI providers
We do not publish a subprocessor list yet. Producing one that we can stand behind means naming every provider that may receive workspace data, the type of data involved, and the region it is processed in — and we would rather publish nothing than publish a list assembled from marketing copy.
If you need the list for a vendor review, request it and we will tell you what is in use at that time.
What this website itself does
This marketing site is a static website with no backend of its own. It does not store what you type. The contact form composes a message in your own email client and sends nothing to a Botnea server until you press send there.
Interface click events are pushed to an in-page data layer so they can be measured later; no third-party analytics or advertising tag is installed on this site today.
Limitations — stated plainly
- Botnea is not SOC 2 certified and not ISO 27001 certified.
- No independent security audit or penetration test is being presented.
- No data processing agreement, subprocessor list, retention schedule, or deletion guarantee is published.
- No SSO, SCIM, audit-log export, or incident-response SLA is claimed.
- No dedicated security mailbox or formal responsible-disclosure programme is established yet; security reports currently go to sales@botnea.com.
- Privacy policy and terms of service are not published yet. We are not putting placeholder legal text online.
- Nothing on this page should be read as a promise of legal compliance for your organisation’s obligations.
Still need something we have not covered?
Ask a specific question and you will get a specific answer, including “we do not have that” where that is the truth.
Contact us