Security — Bonjourchat
Skip to content

Security

Every conversation, kept private.

Your customers trust you with order numbers, addresses and phone calls. Here’s how we protect them — from the data center to the AI.

EU-hosted

Primary in Paris, backups in Frankfurt.

GDPR

DPA included on every plan.

SOC 2 Type II

Report available under NDA.

ISO 27001

Certified information security.

Practices

Secure by default.

01

Encryption

AES-256 at rest, TLS 1.3 in transit. Call recordings and attachments are encrypted with per-workspace keys.

02

Access control

SSO with SAML and SCIM provisioning, enforced two-factor login, and roles that limit who sees which inbox.

03

Audit log

Every sign-in, export, setting change and AI hand-off is logged and exportable to your SIEM.

04

Retention & deletion

Set retention per channel. Customer erasure requests delete a contact across every channel in one action.

05

Infrastructure

Isolated production network, least-privilege access for staff, and encrypted daily backups tested monthly.

06

Testing

Annual third-party penetration tests and a public bug bounty. Summaries shared with customers on request.

AI & your data

Your conversations never train shared models.

Zero retention at model providers

Prompts and replies are not stored or used for training.

PII redaction before inference

Card numbers, IBANs and IDs are masked before any model sees them.

Scoped knowledge

Each AI agent only reads the articles and tools you allow.

Answers you can audit

Every AI reply cites its source and is kept in the thread.

Subprocessors

Who handles your data.

Updated 1 Sep 2026 · 30 days’ notice before changes

ProviderPurposeLocation
ScalewayApplication hosting & databasesParis, FR
Amazon Web ServicesEncrypted backupsFrankfurt, DE
Meta PlatformsWhatsApp Business PlatformDublin, IE
TwilioPhone numbers & voice callsDublin, IE
PostmarkTransactional & inbound emailEU region
StripeBilling & paymentsDublin, IE

Security pack

SOC 2 report, pen test summary, DPA and our completed security questionnaire.

Report a vulnerability

We respond within 24 hours and reward valid findings through our bug bounty.

[email protected]

Contact us to request our PGP key before sending sensitive details.