← Back to AI Front Desk

Security & Trust

How we protect your data

AI Front Desk runs on your customers' websites, so security is built in — not bolted on. Here's what we do today.

🔒 Encryption in transit

All traffic between visitors, the widget, and our servers is encrypted over HTTPS/TLS. Data is never sent in clear text.

🧱 Tenant isolation

Every business is a separate tenant. Bookings, chat history and settings are scoped to a validated client identifier, so one business can never see another's data. Requests for unknown or malformed identifiers are rejected.

🔑 Secrets stay on the server

AI provider keys and notification credentials live only on the backend, never in the widget code that ships to browsers. The embeddable script contains no secrets.

🛡️ Abuse & prompt-injection protection

🤖 Transparent AI

Visitors are clearly told they are talking to an AI assistant at the start of every conversation, by design — aligned with the EU AI Act and US bot-disclosure expectations.

🗄️ Reliable, persistent storage

Bookings and conversations are stored in a managed database with graceful degradation: if the database is briefly unavailable, the widget keeps working instead of failing the visitor.

📤 Your data, your rights

We support access, export and deletion of personal data on request, and we honor the Global Privacy Control (GPC) opt-out signal. We do not sell or share personal data. See our Privacy Policy for details and the full sub-processor list.

📣 Responsible disclosure

Found a security issue? Email mark.ai.ai.solutions@gmail.com and we'll respond promptly. Please give us a chance to fix it before public disclosure.

We follow these practices today. Formal certifications such as SOC 2 and ISO 27001, an EU data-residency option, and independent penetration testing are on our roadmap as we grow. This page describes current practices and is not a contractual warranty.