Security
Your data is safe.
We take security seriously — not as a marketing checkbox, but as a core engineering principle.
🔒
Encryption everywhere
- All data encrypted in transit using TLS 1.3
- Data at rest encrypted with AES-256
- Database connections use SSL certificates
- API keys and secrets stored in environment-level vaults
🏢
Per-organization data isolation
- Every organization's data is strictly isolated at the database level
- No cross-tenant access is possible — even for internal tools
- Role-based access control: Owner, Admin, Partner, Dispatcher, Contractor
- Each user can only access data within their assigned organization
🤖
AI data handling
- AI models (GPT-4o) process your data but do NOT train on it
- Your conversations, contacts, and business data never leave your tenant
- Knowledge Base (RAG) is isolated per organization — one business cannot see another's data
- AI suggestions are always reviewable and overridable before being sent
📋
Data ownership & portability
- You own 100% of your data — we are a processor, not an owner
- Export all your data as CSV at any time
- Delete your account and all data is permanently removed
- We never sell, share, or monetize your data in any way
🔗
Third-party integrations
- Integrations (QuickBooks, Google Calendar, Twilio) connect only at your explicit request
- OAuth-based authentication — we never store third-party passwords
- Webhook communications secured with HMAC signatures
- Each integration can be disconnected at any time
🛡️
Infrastructure & uptime
- Hosted on enterprise-grade infrastructure (Railway, Vercel, Supabase)
- Automated backups with point-in-time recovery
- We strive for 99.9% uptime (as stated in our Terms of Service)
- Monitoring and alerting for all critical services
Sub-processors
| Service | Purpose |
|---|---|
| Railway | Application hosting |
| Supabase | Database & waitlist |
| Vercel | Landing page hosting |
| OpenAI | AI responses & analysis |
| Twilio | SMS messaging |
| Vapi | Voice AI calls |
| Resend | Transactional emails |
| Stripe | Payment processing |
| Intuit (QuickBooks) | Accounting sync |
Security questions?
If you have questions about our security practices, data handling, or need a DPA (Data Processing Agreement), contact us.
hello@bazas.ai