Security

AI security and compliance. Your client data at the core of our architecture.

BillyAI handles sensitive client communications: leads, appointments, records, private conversations. We built the platform with security as the foundation, not as an added feature.

Why AI automation security matters more than ever for SMBs

Data breaches no longer only affect large companies. 43% of cyberattacks target small and medium businesses - and 60% of those that suffer a breach close within 6 months.

When you entrust your client communications to an AI agent, you have the right to know exactly how your data is protected. Here's our answer.

Your data is encrypted. Period.

All data flowing between your clients, your tools, and BillyAI is encrypted in transit via TLS 1.3, the standard used by financial institutions. Data at rest is encrypted with AES-256. Your credentials, API tokens, and access keys are never stored in plain text. They're encrypted with strong hashing algorithms before being saved.

In practice: even in the event of unauthorized access to our servers, your data is unreadable.

No passwords stored. Ever.

All third-party integrations (Google, Meta, Microsoft, Zoho, and others) use the OAuth 2.0 protocol. You authorize BillyAI to access your tools through each platform's official authentication systems. We never see your passwords. We never store them. If you revoke access, the connection is cut instantly.

Built for Canadian and Quebec legal requirements.

CASL / Canadian Anti-Spam Legislation

BillyAI is designed to comply with CASL requirements. Automated communications are only sent to contacts who have given explicit consent. No cold outreach module, no unsolicited mass messaging. Our architecture respects the law, not just works around it.

Law 25 - Personal Information Protection (Quebec)

Law 25 imposes strict obligations on the collection, use, and retention of personal data in Quebec. BillyAI is compliant: minimal collection, declared purpose, access and deletion rights respected, incidents documented and reported per the requirements of the Commission d'accès à l'information.

Hosted in Canada

Your data never leaves Canada.

BillyAI is hosted on Canadian infrastructure. Your client data (conversations, contacts, leads, appointments) stays in Canada, subject to Canadian laws only. No replication to foreign servers, no exposure to external legislation.

For regulated industries (healthcare, real estate, financial services), this is often a non-negotiable requirement. We anticipated it from the start.

Your data is yours. Only yours.

Each BillyAI account is completely isolated at the architecture level. One client's data is never accessible, mixed, or exposed to another client, even accidentally. Each environment is siloed with strict access controls at every layer of the system.

Full traceability. Nothing is invisible.

Every action taken in your account is logged - who did what, on which contact, at what time, from which session. Brain modifications, manual takeovers, configuration changes, API access - everything is tracked and viewable.

In case of questions, disputes, or internal audits, you have a precise, documented answer for every event.

Transparency

What we don't do - and why it matters.

We don't use your conversations to train our AI models
We don't sell your data to third parties
We don't share your client information between accounts
We don't store your passwords or credentials in plain text
We don't send unsolicited communications on behalf of your business without explicit consent
FAQ

Frequently asked questions about security

In Canada. AWS ca-central-1 infrastructure (Montreal), MongoDB Atlas Montreal database. No replication to foreign servers. Your data is subject to Canadian laws only.

No. Your conversations are never used to train AI models. Neither ours nor our providers'. The AI providers we use (Anthropic) contractually commit to not using data transmitted via API for training their models.

Yes. Minimal collection, declared purpose, access and deletion rights respected, incidents documented and reported per the requirements of the Commission d'acces a l'information. Compliance is built into the architecture, not added after the fact.

You export all your data (contacts, conversations, history) in CSV or JSON at any time. Your data belongs to you. No retention, no penalty.

Yes. Each account is completely isolated at the architecture level. Strict access controls at every layer of the system. One client's data is never accessible to another.

Questions about your deployment's security?

We understand that entrusting your client communications to an AI platform requires trust. We're available to answer all your security questions before you even make a decision.