Security Overview
Security and data privacy are foundational to BotSignal.Dev. Because we process website data and interface with external AI models, we have implemented strict protocols to ensure your account and data remain safe.
Infrastructure Security
- Encrypted Transit: All data transmitted between your browser, our servers, and third-party APIs is encrypted using industry-standard TLS (HTTPS).
- Headless Browsing: Our web scrapers utilize secure, isolated headless browser environments to fetch URL data, preventing malicious code from executing on our host servers.
Authentication & Access
- OAuth 2.0: We do not store user passwords. Authentication is handled entirely through Google OAuth, ensuring your login credentials remain secure.
- Session Management: API requests are secured using time-limited tokens. Users can only access, view, or delete audit reports tied directly to their authenticated account ID.
Third-Party Data Processing
We utilize external APIs (such as OpenAI and Anthropic via Vercel) to evaluate website text and generate insights.
- External Inference: We transmit your scraped public website data securely to our AI partners purely for inference processing. While standard enterprise API agreements generally state that customer data is not used to train public models, the ultimate handling and retention of this data are governed strictly by the independent Terms of Service and security policies of those respective providers.
Payment Security
All billing and credit purchases are processed directly through a third party provider. BotSignal.Dev does not collect, process, or store your credit card numbers or banking information on our servers.
Vulnerability Reporting
If you believe you have found a security vulnerability in BotSignal.Dev, please do not disclose it publicly. Email us immediately at support@BotSignal.Dev so we can investigate and patch the issue promptly.