Skip to content

Security

Security and governance

How Buni.ai controls who can change a service, records what changed, and handles your data — including the things we do not offer yet.

Access and roles

Organisations
Each organisation has its own members, and a person can belong to more than one.
Organisation roles
Admin, Supervisor and Member. Admins can do everything, Supervisors everything except delete, and Members see what they are given.
Project roles
Owner, Editor, Viewer, Commenter or Agent on each project, plus access to individual data stores.
Access by area
None, View, Edit or Full access to each area of the product, set per person.
Publishing
Only owners and admins can publish a change to a live service.
Invitations
Sent as a link that expires after seven days by default.

Audit log

An append-only record your admins can read. It records publishes; project access added or removed; connections; API tokens; role assignments; voice numbers and access to call recordings; AI changes applied or rejected; acceptance of the data processing agreement; and every time Buni.ai staff access your organisation’s data.

Individual canvas edits are not logged one by one: each publish creates a version you can compare and restore.

Changing a live service

  • Draft and live are separate. Nothing reaches the people you serve until it is published.
  • Validation runs before every publish and blocks critical problems.
  • Every publish creates a version you can compare with another and restore, with a note.
  • Simulators run every path of a chat, USSD or voice flow before it is published.

Your data

Credentials
Stored encrypted with AES-256-GCM, using a key derived for your organisation.
API tokens
Stored hashed, scoped to what each integration needs, and rate-limited.
Retention
Transcripts and call recordings expire on a window you set — 30, 60, 90, 180 or 365 days — enforced automatically.
Webhooks
Outgoing webhooks are signed. Incoming ones from Stripe, Shopify, GitHub, Slack, Telegram or any HMAC-signed source are verified.
Processing agreement
A versioned data processing agreement, accepted in the product and recorded in the audit log.
Uploads
Audio files are scanned for malware before they are used.

Where data is processed

Buni.ai runs on Amazon Web Services in us-east-1, in the United States. Transfers out of the European Economic Area rely on the European Commission’s Standard Contractual Clauses. BuniAI Ltd is registered in Rwanda. Our sub-processors are listed on the Data privacy page.

Plain answers

The questions procurement teams ask most. If a “no” here is a requirement for you, tell us early — we would rather say it plainly now than have you find it late.

Single sign-on (SSO, SAML)
Not offered today
Multi-factor sign-in
Not offered today
SOC 2, ISO 27001 or HIPAA
None held — and we will not imply otherwise.
In-country or regional hosting
Not offered as standard
Uptime SLA or status page
Not published yet
Approval before publishing
No second approver — publishing is limited to owners and admins.
Exporting your data
Per feature — CSV exports of data stores, chat and USSD activity, and call history. There is no single full export yet.
Deleting your data
Yes — retention expiry is automatic, you can delete your account in the product, and we handle organisation deletion and end-user erasure requests.