Security

Built to keep your data protected.

How business data is handled during the private beta. Confirm your access, integrations, and data requirements with the founder before onboarding.

🔒

Transport and credential protection

  • Data is encrypted in transit using HTTPS/TLS
  • Storage protection and backup retention depend on the infrastructure provider and configuration
  • Integration credentials are handled server-side; do not send passwords or API keys through the website form
🏢

Per-organization data isolation

  • Organization data is isolated through organization-scoped access controls and role-based permissions; authorized operational access may occur for support, security, incident response, maintenance, or legal compliance
  • Access depends on the assigned organization, role, and resource permissions
  • Confirm staff and partner access during onboarding before importing business records
🤖

AI data handling

  • AI is powered by OpenAI; API inputs and outputs are not used to train OpenAI models by default, though data may be processed and temporarily retained under the applicable provider API terms
  • Customer data is logically isolated by organization; selected data is processed by the subprocessors listed below solely to provide requested functionality (voice, messaging, AI, hosting, analytics, payments, bank connectivity)
  • Knowledge Base (RAG) is isolated per organization — one business cannot see another's data
  • Review and takeover rules are agreed before enabling customer-facing automation; some configured workflows can send automatically
📋

Data ownership & portability

  • You retain ownership of your business data
  • Available exports vary by workflow. Agree the required export scope and a migration plan before onboarding
  • Request account deletion; associated data is removed, subject to retention windows and backup rotation
  • We do not sell your business data. Service providers process selected data to deliver the configured features
🔗

Third-party integrations

  • Integrations such as accounting exports, Google Calendar, and Twilio connect only at your explicit request
  • Authentication varies by integration; supported OAuth connections and other credentials are configured during onboarding
  • Webhook communications use provider-supported verification where available
  • Ask the founder for help disconnecting an integration or changing its access
🛡️

Infrastructure & uptime

  • Hosted on managed cloud infrastructure (Railway, Vercel, Supabase)
  • Managed backups and recovery depend on the selected infrastructure provider and plan
  • We work to keep the service reliable and communicate planned maintenance when practical
  • Monitoring of critical services

Sub-processors

ServicePurposeData processed
RailwayCRM application and database hostingCRM records, account and communication data
SupabaseWebsite request storage where configuredWebsite contact details
VercelWebsite and request endpoint hostingWebsite requests, submitted contact details, technical logs
OpenAIAI responses & analysisSelected messages and business context; processing and retention follow applicable API terms
PlaidBank account connectivityFinancial account data, transactions
TwilioSMS & voicePhone numbers, message content
VapiVoice AICall audio, transcripts
ResendEmail deliveryEmail addresses, email content
Payment providerPayment processing when enabledPayment data handled by the approved payment processor
Accounting/export providerFinance handoff when enabledInvoices, payments, or export files at user request
GoogleAnalytics, Calendar, OAuthUsage data, calendar events
MicrosoftClarity website analyticsWebsite usage data, heatmaps, session replay
CloudflareCDN, file storage (R2)Uploaded files (photos, documents)

Providers used depend on your enabled features. Analytics providers process website usage; optional voice, messaging, bank, payment, and calendar integrations process the data needed for those workflows. See the Privacy Policy for details.

Security questions?

If you have questions about our security practices, data handling, or need a DPA (Data Processing Agreement), contact us.

hello@bazas.ai