Security
Last updated: July 29, 2026
Security at BookBot AI
Security is foundational to everything we build. We protect your data with enterprise-grade security measures.
Infrastructure Security
- Hosting: All data is hosted on Supabase (powered by AWS) with SOC 2 Type II certification
- Encryption in Transit: All connections use TLS 1.3 with 256-bit encryption
- Encryption at Rest: All data is encrypted using AES-256
- Network Security: DDoS protection, WAF, and intrusion detection systems
Application Security
- Row-Level Security (RLS): Every database query is scoped to the authenticated user's permissions
- Authentication: Secure authentication via Supabase Auth with bcrypt password hashing
- API Security: All API endpoints require authentication tokens with automatic expiration
- Input Validation: All user inputs are sanitized and validated server-side
- CSRF Protection: Cross-site request forgery protection on all state-changing operations
Payment Security
- PCI DSS Compliant: All payment processing handled by Stripe (PCI Level 1 certified)
- No Card Storage: We never store credit card numbers on our servers
- Stripe Connect: Business owner payouts use Stripe's secure connected accounts
Communication Security
- SMS: Powered by Twilio (A2P 10DLC registered) with enterprise-grade security and compliance
- Voice: Real-time AI voice via Retell with our Gemini brain; carried over Twilio
- Email: Sent via Resend with SPF, DKIM, and DMARC authentication
- Webhook Verification: All incoming webhooks are cryptographically verified
Operational Security
- Regular security audits and vulnerability assessments
- Automated dependency scanning for known vulnerabilities
- Incident response procedures with defined escalation paths
- Employee security training and access controls
Report a Vulnerability
If you discover a security vulnerability, please report it responsibly to support@bookbotai.ai. We take all reports seriously and will respond within 24 hours.
© 2026 BookBot AI.