Skip to main content

Security overview

Biel.ai is designed to meet enterprise security requirements for data protection, compliance, and transparency.

Configurable security features

FeatureDescription
Role-based access (RBAC)Restricts dashboard access to authorized users with segmented permissions.
Domain restrictionsLimits which domains can embed the chatbot widget.
Rate limitingPer-session and per-IP limits to prevent spam and abuse.
PII removalAutomatically detects and redacts names, emails, and phone numbers from conversations.
Bearer authenticationEnforces API key authentication for all API requests.
Granular API permissionsScope each API key to specific permissions (project_read, project_search, create_chat, sources_create).

Security architecture

LayerProtection
NetworkFirewalls, DDoS mitigation, continuous monitoring, and real-time alerts.
Data encryptionEncrypted in transit and at rest. Automated backups for recovery.
Audit logsDetailed logs of security-sensitive operations for accountability.
Account isolationCustomer data is strictly separated between accounts.
Model training opt-outCustomer data is never shared with third-party model training (OpenAI, Anthropic).
GDPR complianceUser data handled in line with European data protection regulations.

See the Privacy Policy for details on data handling.