Legal
Security at ChatOrAI
We take the security of your business data and your customers' conversations seriously. Here's how we protect everything entrusted to us.
- โAll data in transit encrypted with TLS 1.3
- โData at rest encrypted with AES-256
- โJWT tokens signed with HS256 and rotated regularly
- โAPI keys stored encrypted, never logged
- โHosted on Railway with isolated containers
- โCDN and DDoS protection via Cloudflare
- โAutomatic backups every 24 hours
- โZero-downtime deployments
- โRole-based access control (RBAC) across all accounts
- โEach client's data is tenant-isolated
- โAdmin access requires MFA
- โAll access events are logged and auditable
- โGDPR-aligned data handling practices
- โData Processing Agreements available on request
- โMeta platform policies strictly followed
- โRegular internal security reviews
- โContinuous monitoring for anomalies and threats
- โAutomated vulnerability scanning in CI/CD pipeline
- โIncident response plan with <2h SLA
- โSecurity patches applied within 24 hours of disclosure
- โPublic status page at chatorai.com/status
- โIncident postmortems published within 48 hours
- โSecurity changelog maintained
- โResponsible disclosure program active
๐ Responsible Disclosure
Found a security vulnerability? We appreciate responsible disclosure. Please email us at security@chatorai.com with a description of the issue.
We commit to: acknowledging your report within 24 hours ยท providing a timeline for a fix within 72 hours ยท not pursuing legal action against good-faith researchers.
For security concerns or questions, contact us at security@chatorai.com. For general privacy questions, see our Privacy Policy.