Security
Security and governance
How Buni.ai controls who can change a service, records what changed, and handles your data — including the things we do not offer yet.
Access and roles
- Organisations
- Each organisation has its own members, and a person can belong to more than one.
- Organisation roles
- Admin, Supervisor and Member. Admins can do everything, Supervisors everything except delete, and Members see what they are given.
- Project roles
- Owner, Editor, Viewer, Commenter or Agent on each project, plus access to individual data stores.
- Access by area
- None, View, Edit or Full access to each area of the product, set per person.
- Publishing
- Only owners and admins can publish a change to a live service.
- Invitations
- Sent as a link that expires after seven days by default.
Audit log
An append-only record your admins can read. It records publishes; project access added or removed; connections; API tokens; role assignments; voice numbers and access to call recordings; AI changes applied or rejected; acceptance of the data processing agreement; and every time Buni.ai staff access your organisation’s data.
Individual canvas edits are not logged one by one: each publish creates a version you can compare and restore.
Changing a live service
- Draft and live are separate. Nothing reaches the people you serve until it is published.
- Validation runs before every publish and blocks critical problems.
- Every publish creates a version you can compare with another and restore, with a note.
- Simulators run every path of a chat, USSD or voice flow before it is published.
Your data
- Credentials
- Stored encrypted with AES-256-GCM, using a key derived for your organisation.
- API tokens
- Stored hashed, scoped to what each integration needs, and rate-limited.
- Retention
- Transcripts and call recordings expire on a window you set — 30, 60, 90, 180 or 365 days — enforced automatically.
- Webhooks
- Outgoing webhooks are signed. Incoming ones from Stripe, Shopify, GitHub, Slack, Telegram or any HMAC-signed source are verified.
- Processing agreement
- A versioned data processing agreement, accepted in the product and recorded in the audit log.
- Uploads
- Audio files are scanned for malware before they are used.
Where data is processed
Buni.ai runs on Amazon Web Services in us-east-1, in the United States. Transfers out of the European Economic Area rely on the European Commission’s Standard Contractual Clauses. BuniAI Ltd is registered in Rwanda. Our sub-processors are listed on the Data privacy page.
Plain answers
The questions procurement teams ask most. If a “no” here is a requirement for you, tell us early — we would rather say it plainly now than have you find it late.
- Single sign-on (SSO, SAML)
- Not offered today
- Multi-factor sign-in
- Not offered today
- SOC 2, ISO 27001 or HIPAA
- None held — and we will not imply otherwise.
- In-country or regional hosting
- Not offered as standard
- Uptime SLA or status page
- Not published yet
- Approval before publishing
- No second approver — publishing is limited to owners and admins.
- Exporting your data
- Per feature — CSV exports of data stores, chat and USSD activity, and call history. There is no single full export yet.
- Deleting your data
- Yes — retention expiry is automatic, you can delete your account in the product, and we handle organisation deletion and end-user erasure requests.