Vendor security review.
The answers bitbybit publishes, in the order a security questionnaire asks for them. Where a question depends on your specific deployment, this page says so and points you at the person who can answer it, rather than publishing a number that would not hold for every customer.
At a glance
- Data ownership
- Your records, conversations, and tags remain yours
- Export
- Full data export supported
- Encryption
- In transit and at rest
- Access control
- Authenticated; workspace roles scope what each user sees
- Agent auditability
- AI Studio logs what the agent said and did
- Formal certification
- None — not SOC 2, ISO 27001, or HIPAA certified
- Disclosure route
- Published, RFC 9116 at /.well-known/security.txt
- Status transparency
- Public status page with incident history
The certification row is the one buyers most often need early. bitbybit is not SOC 2, ISO 27001, or HIPAA certified. If your review requires an attestation, raise it before you invest time in an evaluation — a straight answer now is worth more than a discovered gap later.
The questions, answered
- What does bitbybit do with customer data, and who owns it?
- bitbybit processes conversations, customer records, and commerce workflows on behalf of the brands that use it. Your customer records, conversation history, and tags remain yours. bitbybit supports full data export, so you can take your customer database with you if you leave. The categories of information collected and processed, the purposes they are used for, how information is shared, and the rights available to you are set out in the Privacy Policy, which is the authoritative statement of bitbybit's data practices.
- Is bitbybit SOC 2, ISO 27001, or HIPAA certified?
- No. bitbybit holds none of those certifications and does not claim to. If a formal third-party attestation is a hard requirement for your review, that is a gap worth surfacing at the start rather than at the end of an evaluation. What bitbybit publishes instead is the practice behind each control area, set out on this page and on the Security and Trust page.
- How is data encrypted?
- bitbybit encrypts personal information in transit and at rest, and applies access controls and authentication mechanisms to the systems that hold it. These safeguards are described in the Data Security section of the Privacy Policy. As that section also states, no method of transmission over the internet or electronic storage is completely secure, and absolute security cannot be guaranteed.
- How is access to customer data controlled?
- Access to systems and to customer information requires authentication and is controlled. Inside the product, workspace roles determine what each member of your team can see and do, so access is scoped per role rather than shared across the workspace. AI Studio keeps logs of what your agent said and did, which makes agent activity reviewable after the fact rather than something taken on trust.
- What third-party providers and sub-processors are involved?
- bitbybit is built on services operated by other companies: messaging platforms, commerce platforms, payment providers, logistics providers, AI providers, and infrastructure vendors. Several are named on the integrations pages, and the categories of provider bitbybit shares information with are set out in the Privacy Policy. Those providers are treated as part of the security surface rather than outside it. For a sub-processor list scoped to your deployment, contact [email protected].
- Where is data stored, and how long is it retained?
- Data-residency regions and retention periods are not published as a single global answer, because they depend on the deployment and the providers involved. Rather than publish a figure that would not hold for every customer, bitbybit handles these during the review: send the question to [email protected] and the team will share the documentation relevant to your deployment.
- What is bitbybit's incident history?
- In August 2026, a security breach affected one of bitbybit's third-party analytics vendors. bitbybit published updates on its public status page as the review progressed, removed the self-hosted third-party analytics component identified during that review, and completed remediation on 30 August 2026. bitbybit has not confirmed that any bitbybit systems or customer information were affected, and any potential impact identified in the initial review would be limited to messaging services. The dated record and the response to third-party claims that followed are published on the security notice.
- How does bitbybit handle vulnerability reports?
- Security researchers report privately to [email protected] with enough detail to reproduce the issue. Machine-readable contact details are published at /.well-known/security.txt in the RFC 9116 format, so scanners and researchers can find the route without asking. Current service state and operational notices are maintained on the public status page.
What this page deliberately does not publish
A trust page that answers every question with a confident number is usually answering some of them with a guess. These are handled in the review instead, because the honest answer depends on your deployment:
- Data-residency regions for a specific workspace
- Retention periods per data category
- The full named sub-processor list for your configuration
- Infrastructure specifics such as cipher suites, TLS versions, or audit cadence
Send those to [email protected] and the team will share the documentation that applies to you.
Related material
- Security & Trust — how bitbybit approaches data protection, access management, third-party services, incident response, and responsible disclosure.
- Security notice — the dated record of the August 2026 third-party analytics vendor breach and the response to third-party claims.
- AI commerce agent buyer checklist — twelve questions worth putting to any platform in this category, bitbybit included.
- Third-party risk in AI commerce platforms — how vendor and sub-processor risk actually reaches a platform, and how to evaluate it.
- Is the WhatsApp Business API secure? — what end-to-end encryption does and does not cover once a business receives a message.
- Privacy Policy — the authoritative statement of bitbybit’s data practices.
- status.bitbybit.studio — live service state and operational notices.
Running a review?
Deployment-specific questions — regions, retention, sub-processors, contractual terms — go to [email protected]. Suspected vulnerabilities go privately to [email protected], not through public channels.