Skip to content

Private by design. Plain about the details.

AI chatbot security, privacy and GDPR

A customer support chatbot handles your customers' words and your AI keys. In Kothadesk the keys are encrypted and never shown again, and your data is isolated in the database, kept only as long as you choose, and exportable or erasable per visitor for GDPR requests. This page lists what exists today, and what does not yet.

Security layersFour nested layers. Network: TLS everywhere, a widget origin allowlist and rate limits. Application: requests for another tenant's data answer not found, keys are scoped, and changes are written to an audit log. Database: row-level security means each query sees one tenant. Secrets: AI keys, the identity secret and memories are encrypted with a per-workspace key. Anything that leaves the platform, such as website crawls and tool calls, goes through an egress proxy that blocks private addresses before reaching the internet.NetworkTLS everywhere, widget origin allowlist, rate limitsApplicationAnother tenant's data answers 404, scoped keys, audit logDatabaseRow-level security: each query sees one tenantSecretsAI keys, identity secret, memories: per-workspace encryptionEgress proxyCrawls and tool callsPrivate addresses blockedThe internetYour site, your tools
Kothadesk Yours, or a third party

01

Your AI keys.

Encrypted per workspace
Envelope encryption with a data key that belongs to your workspace; other secrets such as the identity secret and tool credentials use the same key.
Never shown again
Keys are write-only: never returned by the API, logged, traced or sent to a browser. Only the last four characters are displayed.
Never used for anyone else
Provider clients are built per key; retries and fallbacks stay within your own keys.
Owners and admins only
Adding, rotating and deleting keys is limited to owners and admins, and audited.

02

Your data.

Data handling
AreaDefaultYour control
Tenant isolationRow-level security on every tenant tableNot configurable
ConversationsKept 365 daysShorten per workspace or bot
Visitor IP addressesNot stored in the databaseNot configurable
Long-term memoryOffPer bot; encrypted; signed-in users only
Audit logKept 400 daysReadable by owners and admins
Workspace deletion30-day grace period, then purgedOwners can delete

03

Your visitors' rights under GDPR.

Export
Export everything stored about one visitor, including conversations, memories and call records.
Erase
Erase one visitor and their data; the action is audited with counts only.
Forget me
Signed-in users can ask the assistant to forget what it remembered about them.
Honest answers about privacy
Questions about retention or memory are answered from your real settings and your privacy policy link, never invented.

04

Chatbot guardrails.

Safety checks are always on. Fixed replies from them are written in 30 languages, so a visitor is refused in their own language and script.

Before the model
Jailbreak, prompt extraction, impersonation, abuse and spam checks in six languages, on disguised text too.
After the model
Prompt leaks, unsupported commitments and injected instructions stop an answer before it is shown.
Care for people at risk
Messages about self-harm get an empathetic reply with crisis-line guidance, never a penalty.
Abuse throttling
Repeated abuse cools a visitor down and then blocks them; optional Cloudflare Turnstile per bot.

05

Voice and files.

Calls are not recorded
No recording, no transcription. Audio is relayed without revealing either side's IP address by default.
Files are rebuilt
Types are checked by content; images are re-encoded and stripped of location data and metadata; macro documents are refused.
The model never sees files
Files are for people only: the assistant sees a placeholder, never the file or its name.
Private storage
Files live in private object storage and are served through short-lived signed links.

06

Infrastructure and access.

Egress proxy
Website crawls and tool calls leave through a proxy that refuses private and internal addresses.
Signed sessions
Short-lived access tokens; refresh tokens in an httpOnly cookie, rotated on every use with reuse detection.
Support access by consent
Our staff can see a workspace only after its owner approves, read-only, for up to four hours, in your audit log.
What we do not have yet
No SOC 2 or ISO 27001 certification, and no single sign-on or two-factor sign-in today.

07

Security questions.

Do you support single sign-on or two-factor sign-in?

Not today. Accounts sign in with a verified email and password; sessions rotate with reuse detection, sign-in is rate limited and account changes are audited.

Are you SOC 2 or ISO 27001 certified?

Not yet. This page describes the controls that exist today. We are happy to answer a security questionnaire; write to the security address below.

Can your staff see our conversations?

Only with your consent. Platform support access is off until a workspace owner approves it, is read-only, lasts at most four hours and is written to your audit log.

Where is data stored?

Application data and the database run on Kothadesk's own servers in a Tier IV data centre in India. Uploaded files are kept in private object storage on Cloudflare R2. The subprocessors page lists every third party we use.

Found a vulnerability? Write to [email protected]. Please give us a reasonable time to fix it before disclosure. See also the data processing agreement and privacy policy.

Running a security review?

We will walk your team through the architecture and answer your questionnaire.