Security review
How GetMyBot handles access and data
This page describes product behavior and links to published documents where they support a claim.
What this page does not claim. GetMyBot holds no third-party security certification, publishes no availability commitment, and makes no regulatory compliance claim. If your process needs one of those, tell us which one before you build on the platform.
Who can see what
Access checks run in the application
Every request that names a bot resolves the caller's access to that bot before the handler runs. That check lives in the application layer. Row level security policies exist in the database schema but are not enforced at runtime, and you should hear that from us rather than assume otherwise.
- Access is resolved per request
- The bot in the URL is matched against the accounts you actually have access to, and the resolved access travels with the request instead of being re-derived by each handler.
- Unknown and inaccessible bots return 404
- No access at all answers 404, so a token cannot be used to test whether a bot exists outside its account. Access without the specific right answers 403.
- Rights are per bot, not per account
- Ownership actions such as deletion, transfer and token rotation stay with the owner of the bot and cannot be delegated through the access list at all.
How the keys are kept
Encrypted where they must be read, hashed where they must not
Bot tokens and integration credentials are secrets the service has to use, so they are encrypted. Passwords and API tokens are things it never needs to read back, so they are hashed instead.
- AES-256-GCM at rest
- Bot tokens and integration credentials, including your AI provider key, are encrypted with AES-256-GCM before they reach the database.
- TLS in transit
- All traffic between the apps, the website and our servers goes over TLS, as the published privacy policy states.
- Passwords hashed, second factor available
- Account passwords are stored as argon2id hashes and never in readable form. Time-based one-time-password two-factor authentication is available on the account.
What happens to your prompts
AI routing and recorded content
The provider you configure receives the request. Recorded runs store hashes and sizes of prompts and answers, not their text.
- Provider-neutral routing
- The agent calls an OpenAI-compatible endpoint you configure, with your key. Nothing in the journey logic around it is tied to a particular vendor.
- Prompts and answers are stored as a hash
- When a run is recorded, the prompt and the answer are reduced to a SHA-256 hash of the content plus its size. The text itself is not written to the trace, and there is no separate raw store to read it back from.
- Not used to train models
- The privacy policy states that bot conversations belong to you, are processed to provide the service, and are neither sold nor used to train models.
What you can inspect afterwards
Audit records with redacted content
Content is redacted when the record is created, before anyone can view it.
- The audit trail carries no payloads
- An audit row names the action, the target and the outcome. Its metadata holds identifiers, kinds and counts, never the content of the thing that was acted on.
- Credential-shaped fields run on an allowlist
- An external call keeps its method, address, status and duration; an action keeps its name, its argument names and the kind of result. A field the redactor has never heard of is dropped rather than kept, so a secret cannot leak by being given an unusual name.
- Raw content has nothing to reveal
- Content is redacted on the way in, so there is no unredacted copy to unlock later. The reveal endpoint gates and audits access to fields that were already safe, and stays closed unless the retention class allows it.
How long it stays, and how it leaves
Export, deletion, and retention
Retention periods depend on the data class. Customer export and deletion have API endpoints; account requests follow the published policy.
- Run records expire on a schedule
- The content of a recorded run is the more sensitive half and the shorter-lived one: seven days by default, against thirty, ninety or three hundred and sixty-five days of run metadata depending on the class. Content never outlives metadata.
- Export or delete one customer
- A single subscriber's data can be exported or deleted through the API, and how long each category of customer data is kept is a setting rather than a fixed number.
- Account data requests and required records
- You can ask for a copy of your data, a correction, or its deletion, and the published policy commits to an answer within thirty days. Payment records are kept where accounting rules require it.
Scoped access
Tokens are limited by account, scopes, and expiry
A personal token works within one account and cannot grant rights its owner does not have.
- Read and write are separate scopes
- A scope is a resource plus an action, so a reporting integration can be granted reads without ever being able to write. A missing scope answers 403.
- One token, one account
- A token works in exactly one account. A bot in any other account answers 404, the same answer a stranger gets, so a token cannot be used to probe for ids outside its scope.
- Shown once, stored hashed
- The token value is displayed only at creation. The server keeps a hash of it, so a lost token is reissued rather than recovered, and an expiry can be set when it is created.
Who else touches it
Published processors and hosting region
The processors and hosting region below are the ones named in the privacy policy.
- The service runs in the European Union
- The privacy policy states that the service and its database run with a hosting provider in the European Union. No second region is offered today, and none is claimed.
- The named processors
- Google for analytics, crash reporting and push delivery. Telegram, Meta and VK for the channels you connect. The payment providers that process paid plans. Website analytics run through Matomo and Yandex Metrica.
Need more detail for your review?
Send us the specific question. We will answer it directly, including when the product does not meet a requirement.
Ask a security question