Security & compliance

Security isn't a feature we add at the end. It's how we build.

Whether it's our own product Botnira or a custom AI agent, mobile app or Moodle platform we build for you, we start from the same security baseline — and we can show our work.

Last updated October 7, 2026

Compliance framework

What Botnira's Trust Center documents

Botnira is a production AI receptionist handling real customer calls and messages for businesses, so its compliance program is public. The Trust Center at compliance.botnira.com publishes certificates and documentation for:

ISO/IEC 27001

Information security management.

ISO/IEC 27701

Privacy information management.

SOC 2 Type II

Security and operational controls.

GDPR

Privacy and data-protection documentation for EU data.

PIPEDA

Controls supporting Canada's privacy principles: accountability, consent, limiting collection and more.

Penetration testing

Assessment documentation for completed penetration testing.

Botnira also maintains HIPAA-related documentation but states it is not currently signing additional HIPAA agreements with customers. Certificates, scope and dates are published in the Trust Center — please review them directly for your compliance needs.

Platform controls

Security controls in Botnira

Encryption

TLS protects data in transit between users, applications and Botnira services; stored data is protected with encryption controls.

Access control

Two-factor authentication on supported accounts. Customer data isn't accessible to the Botnira team in ordinary operations.

Network protection

Network firewall controls and DDoS protection help restrict unauthorized and malicious traffic.

Vulnerability management

Regular vulnerability scanning plus completed penetration testing to find weaknesses.

Backups & continuity

Regular database backups, with regional residency applying to backup data, support resilience and recovery.

Incident response

A four-stage process: detection, investigation, containment and remediation.

Data & privacy

Your data stays your data

  • Regional residency options — Canada, United States, European Union, United Kingdom, Australia and India.
  • No training by default — business data submitted to the API platform isn't used to train models unless the organization explicitly opts in.
  • No data sales — the Trust Center contains no language permitting Botnira to sell customer data.
  • Clear retention — applicable data is retained for 45 days after account closure, then permanently deleted. Customers can delete calls and messages while the account is active.
  • Disclosed subprocessors — Twilio (telephony), Meta/WhatsApp (messaging) and OpenAI (AI processing), with a dedicated subprocessor list.

Responsible AI, by design

AI agents can be wrong, so we build around that. Replies are grounded in the business information you supply; human escalation paths are configured for decisions the AI shouldn't make alone; and businesses are expected to disclose to customers when they're talking to an AI.

Read the Responsible AI statement →

Custom builds

How we apply this to your project

Custom AI agents, mobile apps and Moodle platforms don't inherit Botnira's certificates automatically — but they inherit how we work. These are the practices we bring to every engagement:

Least-privilege access

Role-based permissions, separate environments, and credentials kept out of code and handled as secrets.

Encrypted by default

TLS everywhere, and sensitive data protected at rest.

Data minimisation & residency

We collect only what the product needs, and host in the region your users and regulations require.

Guardrails for AI agents

Grounding in approved information, limits on what an agent can do, and human handoff for sensitive cases.

Audit trails & backups

Logging for important actions, and tested backup and recovery plans.

Documented handover

You get clear documentation of what data is processed, where, and by which third-party services.

Specific controls, testing and any certification requirements are defined in each project's scope.

Questions

Security FAQs

Is The DigiSparrow itself ISO 27001 or SOC 2 certified?+
The compliance documentation published in the Botnira Trust Center covers the Botnira platform: ISO/IEC 27001, ISO/IEC 27701, SOC 2 Type II, GDPR, HIPAA-related documentation and completed penetration testing. Custom projects we build for clients are developed with the same security practices as a baseline; whether a specific certification applies to a custom system is agreed per engagement.
Can you build to my industry's compliance requirements?+
We design to your requirements — for example privacy law (PIPEDA, GDPR), data-residency needs, access control and audit logging — and document what the system does and does not cover. Formal certification of a client's own organization is a separate audit, but we can build the technical controls an auditor will ask for.
Do you sign HIPAA agreements?+
Botnira maintains HIPAA-related documentation but states it is not currently signing additional HIPAA agreements with customers. If you handle protected health information, talk to us before starting so we can scope an approach that fits.
Is my data used to train AI models?+
For Botnira, business data submitted to its API platform is not used to train models by default unless the organization explicitly opts in. For custom AI agents, we configure the model provider settings with the same default and put it in writing in the project scope.
Where is data stored?+
Botnira lists regional data-residency options for Canada, the United States, the European Union, the United Kingdom, Australia and India. For custom builds, we choose hosting regions with you based on where your users and regulations require data to live.
How are security incidents handled?+
Botnira follows a four-stage process — detection, investigation, containment and remediation. For custom builds we agree an incident contact and notification process during onboarding.
Can I see your security documents?+
Yes. The Botnira Trust Center publishes its certificates, security overview, data-residency details, subprocessor list and Responsible AI statement. For a custom project, contact us and we will share what is relevant to your review.

Need a security questionnaire answered?

Tell us what your team or regulator requires and we'll tell you honestly what we can deliver.