Security

What happens to your data

You're putting something that talks to your customers on your website. It's fair to want to know where the data goes, who can see it, and how to get rid of it. This page answers that without the usual padding.

Encrypted in transit and at rest

All traffic runs over TLS. Stored data — knowledge sources, conversations and leads — is encrypted at rest.

One tenant, one knowledge base

Your content answers your visitors and nobody else's. Data is separated per workspace and every query is scoped to it.

No training on your content

Your knowledge and conversations are not used to train models — ours or anyone else's. Model providers process content under agreements that prohibit training use.

Where data lives

Openline runs on established cloud infrastructure. Application data sits in managed databases with encryption at rest, automated backups and point-in-time recovery. Uploaded documents are stored in object storage with access restricted to the service.

Enterprise customers can discuss data residency requirements with us before signing — tell us the constraint and we'll tell you honestly whether we can meet it.

Who can see it

  • Your team — through role-based access in the dashboard. Roles limit who can change knowledge, read conversations, export leads or manage billing.
  • Our staff — only when you raise a support request that requires it, when investigating a security incident or suspected abuse, or where the law requires it. Access is role-restricted and logged.
  • Sub-processors — cloud hosting, AI model providers, payment processing, transactional email and error monitoring. Each receives only what it needs, under a data processing agreement. A named list is available on request.
  • Integrations you configure — if you connect a CRM or calendar, the data you mapped goes there because you told us to. You choose whether transcripts are included.

How the AI part works, in security terms

When a visitor asks a question, the agent retrieves the relevant parts of your knowledge base and sends them, with the visitor's message and your instructions, to a model provider to compose a reply. What that means practically:

  • Answers are grounded in content you supplied, not in general knowledge scraped about your company.
  • Content sent for processing is not retained by the provider for training.
  • You control what goes into the knowledge base, so you control what could ever appear in a reply. Don't put anything in there you wouldn't publish.
  • You can lock exact answers for sensitive questions and put topics permanently out of scope.

Account security

  • Passwords are stored hashed, never in plain text
  • Two-factor authentication for dashboard accounts
  • Single sign-on and audit logs on Enterprise
  • Session management with the ability to revoke active sessions
  • API keys are scoped, revocable and shown once

The widget on your site

The chat widget is a small script served from our CDN and loaded asynchronously, so it doesn't block your page. It runs in your visitors' browsers with the minimum permissions it needs, and it doesn't read your page's form fields or track visitors across other websites. It sets a first-party identifier so a conversation survives a page refresh — that's all.

Retention and deletion

  • Set automatic conversation deletion at 30, 90, 180 or 365 days
  • Delete an individual conversation, lead or knowledge source at any time
  • Export everything — conversations, leads and knowledge — whenever you want it
  • Close your account and content is deleted or irreversibly anonymised within 30 days, other than records we must keep for tax and accounting
  • Visitor deletion requests are honoured; the fastest route is usually through the business whose site they used

Resilience

Automated backups with point-in-time recovery, monitoring with alerting on availability and error rates, and staged deploys with the ability to roll back. If there's an incident that affects your data, we'll tell you promptly, tell you what we know, and tell you what we're doing about it — including the parts that don't flatter us.

Certifications

We're not going to claim compliance certifications we don't hold. If a formal audit is a requirement for your business, talk to us and we'll tell you exactly where we are and what our timeline looks like, rather than sending you a badge.

Reporting a vulnerability

If you've found a security issue, please email security@openline.ai with enough detail to reproduce it. We'll acknowledge within two working days, keep you updated, and won't pursue researchers who report in good faith, avoid privacy violations and give us a reasonable window to fix the issue before disclosing it.

Questions before you buy

Security reviews, data processing agreements, sub-processor lists and questionnaires: security@openline.ai. We'd rather answer twenty questions now than discover a mismatch after you've gone live.

Control

Security is also about what it's allowed to say

Most of the risk in putting AI on a customer-facing site isn't a breach — it's the agent confidently saying something you'd never say. Those controls are part of the product, not an add-on.

  • Answers restricted to knowledge you approved
  • Written instructions for tone, limits and refusals
  • Topics you can put permanently off-limits
  • Word-for-word locked answers for sensitive questions
  • Escalation to a human on demand or on trigger
  • Every conversation logged and reviewable
We don't claim the agent is right one hundred per cent of the time — nobody honestly can. We give you the tools to see what it says, correct it permanently, and decide where it stops.

Try it, read the logs, decide.

14 days with the full feature set. Every conversation it has is visible to you from the first minute.