Security

Built to keep your data protected.

We take security seriously — not as a marketing checkbox, but as a core engineering principle.

🔒

Encryption everywhere

  • Data is encrypted in transit using HTTPS/TLS
  • Data at rest is protected using provider-managed encryption
  • Database connections use SSL certificates
  • API keys and secrets stored in environment-level vaults
🏢

Per-organization data isolation

  • Every organization's data is strictly isolated at the database level
  • Organization data is isolated through organization-scoped access controls and role-based permissions; authorized operational access may occur for support, security, incident response, maintenance, or legal compliance
  • Role-based access control: Owner, Admin, Partner, Dispatcher, Contractor
  • Each user can only access data within their assigned organization
🤖

AI data handling

  • AI is powered by OpenAI; API inputs and outputs are not used to train OpenAI models by default, though data may be processed and temporarily retained under the applicable provider API terms
  • Customer data is logically isolated by organization; selected data is processed by the subprocessors listed below solely to provide requested functionality (voice, messaging, AI, hosting, analytics, payments, bank connectivity)
  • Knowledge Base (RAG) is isolated per organization — one business cannot see another's data
  • AI suggestions are reviewable and overridable before being sent
📋

Data ownership & portability

  • You own 100% of your data — we are a processor, not an owner
  • Export all your data as CSV at any time
  • Request account deletion; associated data is removed, subject to retention windows and backup rotation
  • We never sell, share, or monetize your data in any way
🔗

Third-party integrations

  • Integrations such as accounting exports, Google Calendar, and Twilio connect only at your explicit request
  • OAuth-based authentication — we never store third-party passwords
  • Webhook communications use provider-supported verification where available
  • Each integration can be disconnected at any time
🛡️

Infrastructure & uptime

  • Hosted on managed cloud infrastructure (Railway, Vercel, Supabase)
  • Managed backups and recovery depend on the selected infrastructure provider and plan
  • We work to keep the service reliable and communicate planned maintenance when practical
  • Monitoring of critical services

Sub-processors

ServicePurpose
RailwayApplication hosting
SupabaseDatabase & authentication
VercelWebsite hosting
OpenAIAI responses & analysis
PlaidBank account connectivity
TwilioSMS & voice
VapiVoice AI
ResendEmail delivery
Payment providerPayment processing when enabled
Accounting/export providerFinance handoff when enabled
GoogleAnalytics, Calendar, OAuth
MicrosoftClarity website analytics
CloudflareCDN, file storage (R2)

Security questions?

If you have questions about our security practices, data handling, or need a DPA (Data Processing Agreement), contact us.

hello@bazas.ai