Skip to content
BoloBots

Security

Built so one client's data never shows up in another's workspace.

A plain-language summary. The full security model, data map, threat model, and incident process are maintained with the source code.

Tenant isolation in the database

Every tenant query runs under a restricted Postgres role with row-level security, so one agency can never read another's records — even if a query forgets a filter.

Encrypted social tokens

Access and refresh tokens are sealed with AES-256-GCM, never sent to the browser, and deleted on disconnect.

Expiring, revocable links

Approval, portal, intake, and report links are opaque, hashed at rest, expire on schedule, and can be revoked at any time.

Audit trail

Approvals, schedule changes, publishes, replies, exports, and settings changes are logged with actor, time, and correlation ID.

Least privilege

Nine organization roles and optional per-client restriction. API keys are scoped, hashed, expiring, and start in dry-run mode.

Honest limits

No compliance certification is claimed. We publish our data map, threat model, and incident process instead.

How data is protected

  • Passwords are hashed with bcrypt; sessions are random tokens stored only as keyed hashes, sent in HttpOnly, SameSite cookies.
  • Login, signup, reset, approval links, forms, and API keys are rate-limited in the database so limits hold across servers.
  • Uploads are verified by their content, size-limited, and served only after a tenant check — storage paths are never used as permission.
  • Outgoing redirects only follow stored, signed http(s) links. Strict security headers and a content security policy apply to every page.
  • Personal data is redacted before text is sent to an AI provider, and AI can be switched off per organization.

What we don't claim

  • No HIPAA, GDPR, DPDP, or SOC 2 certification is claimed. Those require completed legal and technical programs.
  • Clinic and healthcare templates are for marketing and lead follow-up only. Diagnoses, treatment records, and clinical history must not be stored.
  • Reports show association between activity and outcomes, not proof of cause.

Report a vulnerability to the support address in the footer. We acknowledge within two business days.