Trust

Vendor security review.

The answers bitbybit publishes, in the order a security questionnaire asks for them. Where a question depends on your specific deployment, this page says so and points you at the person who can answer it, rather than publishing a number that would not hold for every customer.

Last updated: 2026-09-04

At a glance

Data ownership
Your records, conversations, and tags remain yours
Export
Full data export supported
Encryption
In transit and at rest
Access control
Authenticated; workspace roles scope what each user sees
Agent auditability
AI Studio logs what the agent said and did
Formal certification
None — not SOC 2, ISO 27001, or HIPAA certified
Disclosure route
Published, RFC 9116 at /.well-known/security.txt
Status transparency
Public status page with incident history

The certification row is the one buyers most often need early. bitbybit is not SOC 2, ISO 27001, or HIPAA certified. If your review requires an attestation, raise it before you invest time in an evaluation — a straight answer now is worth more than a discovered gap later.

The questions, answered

What does bitbybit do with customer data, and who owns it?
bitbybit processes conversations, customer records, and commerce workflows on behalf of the brands that use it. Your customer records, conversation history, and tags remain yours. bitbybit supports full data export, so you can take your customer database with you if you leave. The categories of information collected and processed, the purposes they are used for, how information is shared, and the rights available to you are set out in the Privacy Policy, which is the authoritative statement of bitbybit's data practices.
Is bitbybit SOC 2, ISO 27001, or HIPAA certified?
No. bitbybit holds none of those certifications and does not claim to. If a formal third-party attestation is a hard requirement for your review, that is a gap worth surfacing at the start rather than at the end of an evaluation. What bitbybit publishes instead is the practice behind each control area, set out on this page and on the Security and Trust page.
How is data encrypted?
bitbybit encrypts personal information in transit and at rest, and applies access controls and authentication mechanisms to the systems that hold it. These safeguards are described in the Data Security section of the Privacy Policy. As that section also states, no method of transmission over the internet or electronic storage is completely secure, and absolute security cannot be guaranteed.
How is access to customer data controlled?
Access to systems and to customer information requires authentication and is controlled. Inside the product, workspace roles determine what each member of your team can see and do, so access is scoped per role rather than shared across the workspace. AI Studio keeps logs of what your agent said and did, which makes agent activity reviewable after the fact rather than something taken on trust.
What third-party providers and sub-processors are involved?
bitbybit is built on services operated by other companies: messaging platforms, commerce platforms, payment providers, logistics providers, AI providers, and infrastructure vendors. Several are named on the integrations pages, and the categories of provider bitbybit shares information with are set out in the Privacy Policy. Those providers are treated as part of the security surface rather than outside it. For a sub-processor list scoped to your deployment, contact [email protected].
Where is data stored, and how long is it retained?
Data-residency regions and retention periods are not published as a single global answer, because they depend on the deployment and the providers involved. Rather than publish a figure that would not hold for every customer, bitbybit handles these during the review: send the question to [email protected] and the team will share the documentation relevant to your deployment.
What is bitbybit's incident history?
In August 2026, a security breach affected one of bitbybit's third-party analytics vendors. bitbybit published updates on its public status page as the review progressed, removed the self-hosted third-party analytics component identified during that review, and completed remediation on 30 August 2026. bitbybit has not confirmed that any bitbybit systems or customer information were affected, and any potential impact identified in the initial review would be limited to messaging services. The dated record and the response to third-party claims that followed are published on the security notice.
How does bitbybit handle vulnerability reports?
Security researchers report privately to [email protected] with enough detail to reproduce the issue. Machine-readable contact details are published at /.well-known/security.txt in the RFC 9116 format, so scanners and researchers can find the route without asking. Current service state and operational notices are maintained on the public status page.

What this page deliberately does not publish

A trust page that answers every question with a confident number is usually answering some of them with a guess. These are handled in the review instead, because the honest answer depends on your deployment:

  • Data-residency regions for a specific workspace
  • Retention periods per data category
  • The full named sub-processor list for your configuration
  • Infrastructure specifics such as cipher suites, TLS versions, or audit cadence

Send those to [email protected] and the team will share the documentation that applies to you.

Running a review?

Deployment-specific questions — regions, retention, sub-processors, contractual terms — go to [email protected]. Suspected vulnerabilities go privately to [email protected], not through public channels.