Security isn't a feature we add at the end. It's how we build.
Whether it's our own product Botnira or a custom AI agent, mobile app or Moodle platform we build for you, we start from the same security baseline — and we can show our work.
Last updated October 7, 2026
What Botnira's Trust Center documents
Botnira is a production AI receptionist handling real customer calls and messages for businesses, so its compliance program is public. The Trust Center at compliance.botnira.com publishes certificates and documentation for:
ISO/IEC 27001
Information security management.
ISO/IEC 27701
Privacy information management.
SOC 2 Type II
Security and operational controls.
GDPR
Privacy and data-protection documentation for EU data.
PIPEDA
Controls supporting Canada's privacy principles: accountability, consent, limiting collection and more.
Penetration testing
Assessment documentation for completed penetration testing.
Botnira also maintains HIPAA-related documentation but states it is not currently signing additional HIPAA agreements with customers. Certificates, scope and dates are published in the Trust Center — please review them directly for your compliance needs.
Security controls in Botnira
Encryption
TLS protects data in transit between users, applications and Botnira services; stored data is protected with encryption controls.
Access control
Two-factor authentication on supported accounts. Customer data isn't accessible to the Botnira team in ordinary operations.
Network protection
Network firewall controls and DDoS protection help restrict unauthorized and malicious traffic.
Vulnerability management
Regular vulnerability scanning plus completed penetration testing to find weaknesses.
Backups & continuity
Regular database backups, with regional residency applying to backup data, support resilience and recovery.
Incident response
A four-stage process: detection, investigation, containment and remediation.
Your data stays your data
- Regional residency options — Canada, United States, European Union, United Kingdom, Australia and India.
- No training by default — business data submitted to the API platform isn't used to train models unless the organization explicitly opts in.
- No data sales — the Trust Center contains no language permitting Botnira to sell customer data.
- Clear retention — applicable data is retained for 45 days after account closure, then permanently deleted. Customers can delete calls and messages while the account is active.
- Disclosed subprocessors — Twilio (telephony), Meta/WhatsApp (messaging) and OpenAI (AI processing), with a dedicated subprocessor list.
Responsible AI, by design
AI agents can be wrong, so we build around that. Replies are grounded in the business information you supply; human escalation paths are configured for decisions the AI shouldn't make alone; and businesses are expected to disclose to customers when they're talking to an AI.
How we apply this to your project
Custom AI agents, mobile apps and Moodle platforms don't inherit Botnira's certificates automatically — but they inherit how we work. These are the practices we bring to every engagement:
Least-privilege access
Role-based permissions, separate environments, and credentials kept out of code and handled as secrets.
Encrypted by default
TLS everywhere, and sensitive data protected at rest.
Data minimisation & residency
We collect only what the product needs, and host in the region your users and regulations require.
Guardrails for AI agents
Grounding in approved information, limits on what an agent can do, and human handoff for sensitive cases.
Audit trails & backups
Logging for important actions, and tested backup and recovery plans.
Documented handover
You get clear documentation of what data is processed, where, and by which third-party services.
Specific controls, testing and any certification requirements are defined in each project's scope.
Security FAQs
Is The DigiSparrow itself ISO 27001 or SOC 2 certified?+
Can you build to my industry's compliance requirements?+
Do you sign HIPAA agreements?+
Is my data used to train AI models?+
Where is data stored?+
How are security incidents handled?+
Can I see your security documents?+
Need a security questionnaire answered?
Tell us what your team or regulator requires and we'll tell you honestly what we can deliver.