Core Policy

Security Policy

Effective: 30 April 2026

Last Modified: May 2026

Version 3.1

BOTVEE (PRIVATE) LIMITED  ·  SECP: 0326112  ·  FBR: I510669

Standards Alignment

Security practices guided by: OWASP Top 10, NIST Cybersecurity Framework (CSF 2.0), CIS Controls v8, ISO/IEC 27001 principles, PECA 2016, Pakistan National Cyber Security Policy (NCSP), and PKCERT guidelines. Supabase and Vercel maintain SOC 2 compliance programs.

1

Our Security Commitment

BOTVEE (PRIVATE) LIMITED treats data security as a core business obligation. This policy describes the technical and organisational measures protecting personal data, platform integrity, and service availability. All Botvee systems, data flows, and personnel are subject to this policy.

2

Encryption

  • In transit: TLS 1.2 minimum (TLS 1.3 preferred) enforced on all pages, API endpoints, and WebSocket connections. HTTP automatically redirected to HTTPS on all domains.
  • At rest: AES-256 encryption for all stored personal data and database contents, implemented through Supabase's encrypted storage layer.
  • Passwords: Bcrypt hashing with minimum cost factor 12. Original passwords are never stored in any readable form and are not accessible to any person including Botvee staff.
  • Backups: All backup data encrypted using AES-256 before storage.
  • Secrets & API keys: Stored in secure vault environments — never committed to source code or version-controlled repositories.
3

Access Controls

  • Role-Based Access Control (RBAC): employees access only the data and systems required for their specific role
  • Workspace RBAC for customers: owner, admin, agent, and viewer roles scope exactly what each teammate can see and do
  • Account 2FA: TOTP-based two-factor authentication with recovery codes and login-attempt throttling
  • Principle of Least Privilege: all permissions restricted to the minimum necessary
  • MFA mandatory for all internal admin systems, cloud infrastructure consoles, and production environments
  • Comprehensive audit logging: all access events logged with timestamp, user identity, IP address, and action taken
  • Access privilege reviews conducted quarterly
  • Access revoked within 24 hours of employee departure or role change
  • Production data strictly prohibited in development and testing environments
4

Infrastructure Security

  • Platform hosted on Supabase (database/auth) and Vercel (application) — both maintaining SOC 2 compliance programs
  • Enterprise-grade edge network and DDoS mitigation through hosting infrastructure
  • Platform-level protections against OWASP Top 10 vectors including SQL injection, XSS, CSRF, and path traversal
  • Automated dependency vulnerability scanning across the codebase and build pipeline
  • Internal security assessments conducted on an ongoing basis as the platform evolves
  • Critical vulnerabilities prioritised for patching within 24 hours of confirmed identification; high severity within 7 days
  • Automated monitoring with alerting for anomalous traffic and unusual access patterns
  • PKCERT advisories and guidelines monitored for national-level threat intelligence
5

Secure Development

  • OWASP Top 10 secure coding guidelines followed by all development team members
  • Mandatory peer code review required before any deployment to production
  • Input validation and output encoding on all user-facing and API inputs
  • Automated dependency vulnerability scanning in the CI/CD pipeline
  • Strict environment separation: development, staging, and production are isolated
  • Regular security awareness training for all development and operations personnel
6

Data Backup & Business Continuity

  • Automated daily backups of all user and platform data
  • Backups stored in geographically separated locations
  • Backup integrity verified monthly; full restoration procedures tested quarterly
  • Recovery Time Objective (RTO): target 4 hours for critical systems
  • Recovery Point Objective (RPO): maximum 24-hour data loss in worst-case scenario
  • Business continuity plan reviewed and updated annually
7

Incident Response

7.1 Response Process

  1. Detection — automated monitoring alerts within minutes of anomaly detection
  2. Triage & Containment — affected systems isolated within 1 hour of confirmed incident
  3. Assessment — scope, impact, and affected data assessed within 4 hours
  4. Notification — material incidents: affected users notified within 24 hours; regulatory notification per applicable timelines
  5. Remediation — root cause identified, addressed, and controls hardened
  6. Post-Incident Review — lessons learned documented and implemented within 30 days

7.2 Data Breach Notification

  • Where legally required, relevant supervisory authorities notified without undue delay, including within 72 hours where required under GDPR Art.33
  • Pakistan: notification to FIA Cybercrime Wing and PKCERT where required under applicable Pakistani law
  • Affected users notified without undue delay where breach is likely to result in high risk to their rights and freedoms
  • All incidents documented internally in a breach register regardless of whether they meet formal notification thresholds
8

Subprocessor Security

ProviderSecurity CertificationKey Measures
SupabaseSOC 2 compliance programAES-256 at rest, TLS in transit, GDPR DPA available
VercelSOC 2 compliance programEnterprise DDoS protection, GDPR DPA available
StripePCI-DSS Level 1 (highest)Never shares card data; full payment security
OpenAIContractual safeguardsAPI data not used for training; enterprise data protections
9

Responsible Disclosure

Security researchers are invited to report vulnerabilities responsibly to security@botvee.ai — Subject: "Security Vulnerability Report". Botvee commits to: acknowledge within 48 hours; investigate and respond within 14 days for critical issues; not pursue legal action against good-faith reporters; provide formal recognition for verified critical/high severity findings.

10

User Security Responsibilities

  • Use strong, unique passwords (minimum 12 characters, mixed case, numbers, symbols)
  • Enable two-factor authentication (TOTP) in your account security settings and store your recovery codes safely
  • Keep login credentials strictly confidential — do not share with others
  • Report any suspected security issues immediately to support@botvee.ai
  • Do not access Botvee on unsecured public Wi-Fi without a trusted VPN
11

Applicable Standards & Laws

  • Pakistan: PECA 2016 (amended 2025), Constitution Art.14, PDPB 2023 (draft principles), NCSP, PKCERT guidelines
  • EU/UK: GDPR Art.32 (appropriate technical and organisational measures), UK GDPR
  • International: NIST CSF 2.0, CIS Controls v8, ISO/IEC 27001 principles (not certified)
  • Payment: PCI-DSS (implemented through Stripe)
12

Contact

Security Reports

security@botvee.ai

Company

BOTVEE (PRIVATE) LIMITED

BOTVEE (PRIVATE) LIMITED

Version 3.1  ·  May 2026