Trust

Security and trust at bitbybit.

bitbybit runs conversations, customer records, and commerce workflows on behalf of the brands that use it. This page describes how we approach protecting that information, how we respond when something needs investigating, and where to reach us.

Last updated: 2026-08-29

Security at bitbybit

Security is considered across application development, infrastructure, access management, third-party services, and operational processes. It is treated as an ongoing programme rather than a fixed checklist: the platform, the integrations it depends on, and the threats it faces all change, so the work of protecting customer information is continuous.

This page is written to be useful to the people who actually ask — operators evaluating bitbybit, security teams reviewing a vendor, and researchers who have found something. Where a topic is governed by a formal document, we link to that document rather than paraphrase it.

If you are running a vendor review, the questions worth putting to any platform in this category — data ownership, export, permission boundaries, and auditability — are set out in our AI commerce agent buyer checklist, and the system model those questions probe is described in the AI commerce platform architecture guide.

Customer data

The categories of information bitbybit collects and processes, the purposes it is used for, how it is shared, and the rights available to you are set out in the Privacy Policy. That document is the authoritative statement of our data practices; this page does not modify it.

Access management

Access to systems and to customer information is controlled, and authentication is required to reach them. Inside the product, workspace roles determine what each member of your team can see and do, and AI Studio keeps logs of what your agent said and did, so agent activity can be reviewed after the fact.

Infrastructure and data protection

bitbybit encrypts personal information in transit and at rest, and applies access controls and authentication mechanisms to the systems that hold it. These safeguards are described in the Data Security section of the Privacy Policy.

As that section also states plainly: no method of transmission over the internet or electronic storage is completely secure, and absolute security cannot be guaranteed. We would rather say that than imply otherwise.

Third-party services

bitbybit is built on top of services operated by other companies — messaging platforms, commerce platforms, payment providers, logistics providers, AI providers, and infrastructure vendors. Several of these are named on the integrations pages, and the categories of provider we share information with are set out in the Privacy Policy.

Third-party providers are part of the security surface, not outside it. Events affecting a provider are evaluated the same way as events affecting our own systems: on their potential impact on customers, information, and service availability.

WhatsApp is bitbybit's flagship channel and runs on Meta's infrastructure. For how WhatsApp Business Platform encryption works and what that does and doesn't cover once a business receives a message, see is the WhatsApp Business API secure?

Incident response

Security events are evaluated based on their potential impact on customers, information, and service availability. When an issue requires investigation, bitbybit works to contain the issue, understand its scope, remediate identified risks, and communicate material updates through appropriate channels.

Investigations do not begin with conclusions. Findings about scope, cause, and impact are established through the investigation itself, and what we publish reflects what has actually been established at the time of writing.

Responsible disclosure

Security researchers who believe they have identified a vulnerability affecting bitbybit Studio should report it privately so our team can investigate responsibly.

Report a vulnerability

Email [email protected] with enough detail to reproduce the issue — the affected endpoint or surface, the steps you took, and what you observed. Please do not access, modify, or retain data belonging to other people while investigating, and please give us a reasonable opportunity to respond before disclosing publicly.

Machine-readable contact details are published at /.well-known/security.txt.

Service availability

Current service status, maintenance information, and operational security updates are maintained on the public bitbybit status page.

Service status

status.bitbybit.studio →

The status page is the source for live service state and for operational notices as they are updated.

Security notices

Where a security matter warrants a standing, first-party explanation beyond an operational status update, we publish it here.

Contact