Your customers' conversations, your business knowledge, and your leads are some of your most sensitive assets. We protect them with strong encryption, strict tenant isolation, and a simple promise: your data is yours, and it's never used to train anyone's model.
TLS in transit, AES-256-GCM for secrets at rest.
Every record is scoped to your account. No cross-tenant leakage.
Your content is used to answer your visitors — nothing else.
Automated, encrypted, off-site snapshots you can be restored from.
Concrete controls, described plainly — so you know exactly what happens to your data.
All traffic between your visitors, your dashboard, and our servers runs over HTTPS/TLS. Credentials, chats, and API calls are never sent in the clear.
Sensitive secrets — integration tokens, connected-channel credentials, provider API keys — are encrypted with AES-256-GCM before they ever touch the database, with authenticated encryption to detect tampering.
The platform is multi-tenant by design: every query is scoped to your workspace ID. One customer can never see, search, or export another customer's bots, conversations, or leads.
Account passwords are hashed with bcrypt and never stored or logged in plain text. We can't see your password — and neither can anyone who reads the database.
Sessions use signed JWT tokens with a per-user version stamp. Changing your password or signing out everywhere instantly invalidates every old token.
Your database is snapshotted automatically on a rolling schedule and stored, encrypted, in a private off-site repository — so a bad deploy or hardware failure never means lost data.
We are a tool, not a training set. The knowledge you upload and the conversations your bot has stay inside your workspace — we do not use them to train foundation models, we do not sell them, and we do not share them with other customers.
You stay in control of the full lifecycle: export your data when you want it, and delete it when you're done. When you delete a bot, its sources and conversations go with it.
See what we collect & why →Least-privilege access, so the right people have exactly the access they need — and no more.
Invite teammates as Owner, Member, Support, or Viewer. Only the owner can manage billing, members, and API keys. Roles can never be silently escalated to owner.
Programmatic keys are shown once at creation and never displayed again. Each key is tied to a single workspace, and any key can be revoked instantly if it's ever exposed.
Payments run through Stripe and PayPal hosted checkout. Card numbers never reach our systems — we only ever store a subscription reference, so PCI scope stays with the processors.
A support agent is only trustworthy if it stays inside the lines you draw. AI SNS CHAT gives you the controls.
Whitelist or blacklist topics so the bot answers what it should and politely declines the rest — no wandering off into areas you never approved.
Force answers to cite the documents you provided. This keeps replies accurate and dramatically reduces the risk of confident, made-up answers.
Run on Anthropic Claude, OpenAI, Google Gemini, and more. Your keys, your provider's data terms — you're never locked into a single vendor's policy.
We favor boring, proven infrastructure over clever fragility: predictable databases, clear logs, and automated recovery. If something breaks, encrypted snapshots let us restore quickly with minimal data loss.
AI SNS CHAT is built and operated by Freeborn Co., Ltd (株式会社フリーボーン), an IT-services company established in 2000 with over two decades of handling sensitive customer systems across Japan.
Pursuing SOC 2 and ISO 27001 as we grow — happy to share our current posture under NDA.
We welcome responsible disclosure from the security community. If you believe you've found a security issue, please report it privately and give us a reasonable window to fix it before any public disclosure. We won't pursue action against good-faith research.
Report a security issueNo. Your uploaded knowledge and chat logs are used only to answer your own visitors. We don't train foundation models on your data or share it with other customers.
No. The platform is isolated per workspace — every data query is scoped to your account ID, so there is no path for one tenant to read another tenant's data.
Traffic is protected with TLS/HTTPS in transit. Secrets such as integration tokens and provider API keys are encrypted with AES-256-GCM at rest, and passwords are hashed with bcrypt.
They aren't — on our servers at least. All card processing happens on Stripe's and PayPal's hosted checkout. We only store a subscription reference, never card numbers.
Deleting a bot removes its sources and conversations. You can export your data beforehand, and deletions propagate out of backups on the next rotation.
Yes. Assign Owner, Member, Support, or Viewer roles per teammate. Only owners manage billing, members, and API keys, and roles can't be escalated to owner through the API.
Yes. Your database is snapshotted automatically on a rolling schedule and stored encrypted in a private off-site location, so we can recover quickly from failures.
We're happy to walk your team or your security reviewers through our controls in detail.
Get in touch