The practices that keep your content and your visitors' conversations protected.
Last updated July 5, 2026
All traffic is encrypted in transit with TLS 1.3. Data at rest is encrypted with AES-256. Secrets and API keys are stored in a managed secrets vault, never in application code.
You own the content you connect and every conversation your agent has. Snippets are sent to LLM providers only to generate answers, under contracts that prohibit training their models on that data. We do not sell your data.
Access to production systems is least-privilege and role-based, protected by SSO and multi-factor authentication for our team. Within your workspace, you control who can see and manage each agent.
The platform runs on reputable cloud providers with network isolation, automated patching, and continuous monitoring. Backups are encrypted and tested.
We monitor availability continuously and design for graceful degradation so your agent keeps answering. Enterprise plans can include an uptime SLA.
You can delete individual sources or conversations anytime. On account closure we delete or anonymize your data within 30 days unless a longer period is legally required.
We use a small set of vetted sub-processors (hosting, LLM inference, analytics, email, payments), each under a data-processing agreement. A current list is available on request.
Found a vulnerability? Please report it privately to security@sitegpt.omazy.ai. We investigate every report and will work with you on a fix; we ask that you give us reasonable time before public disclosure.
We build to align with GDPR and CCPA obligations and offer a Data Processing Addendum. If your procurement process needs specific documentation, contact security@sitegpt.omazy.ai and we'll help.