Security

Trust, data safety & control

What is implemented on this website today, and what is configured per client project for deployed agents.

Website security (implemented)

Controls active on this marketing site and lead forms.

Hosting & database

The website, CDN and server functions run on Netlify; application data is stored in a managed PostgreSQL database on Neon. Data location depends on the configured provider region and may be outside Uzbekistan.

Server-side validation

Zod schemas validate all lead and registration payloads.

Consent required

Forms require explicit consent with links to legal pages.

Rate limiting

Persistent per-IP, per-email and per-session limits are enforced in PostgreSQL, so they hold across serverless invocations.

Honeypot field

Hidden field filters basic bot submissions.

Request IDs

API responses include IDs for support tracking.

Secrets server-side

Database and auth secrets stay in server environment variables.

Agent deployment controls (per project)

Configured individually when your agent is built — not automatic for every integration.

Limited permissions

Agents receive only the API scopes you approve.

Action confirmation

Critical operations can require human approval.

Data separation

Customer data should be isolated per project/account.

Retention settings

Conversation history retention period can be configured.

Human handoff

Dialogs can be transferred to staff with full context.

Integration access

Depends on tokens and permissions you grant.

Safe logging

Logs must not expose API secrets or full payment data.

Future AI deployments add provider-specific controls. Exact settings depend on your contract and architecture.

Your data on this website

Lead submissions are validated before being stored in the managed PostgreSQL database on Neon, and registration uses hashed passwords. We do not sell personal data. Where data is stored depends on the configured provider region and may be outside Uzbekistan; see the Privacy Policy for details. This describes the current public website. Custom client agent deployments may use different infrastructure, and their data retention and hosting are agreed separately for each project.

Request a consultation

Tell us about your business — we will respond with next steps.