Safe by design, private by default.
MagizAI is built multi-tenant with encryption, strict guardrails, and hard limits on what the AI can see and do. Here's how we keep your data and your customers safe.
Every connector token and AI key is stored encrypted, per tenant, and never returned by the API.
Use your own AI provider keys so prompts and data flow through your account, not a shared one.
Training fetches validate resolved IPs, block private ranges, pin DNS, and cap size, no server-side request forgery.
No hallucinated facts or prices, stay-on-topic enforcement, and graceful fallback on every AI call.
Each workspace is isolated; suspended tenants are locked out of app, API and portal by middleware.
Every AI call is logged with tokens and cost, and sensitive actions carry a full audit trail.
Visitors paste card numbers into chat whatever you ask them not to. We detect and mask them before the first write, so they never reach the database, the transcript, or your AI provider. Only the last four survive.
A page you train on could contain instructions aimed at your bot. Retrieved content is stripped of instruction-shaped text and fenced as data, so a crawled page can inform an answer but never issue an order.
Export or erase everything held about one visitor: transcripts, contact details, browsing profile and remembered facts. Conversations are deleted, not anonymised, because a transcript still names the person. Every erasure is audit-logged.
The widget is keyboard-navigable, screen-reader-labelled and closes on Escape, with visible focus throughout. Chat widgets are a common target of accessibility complaints; ours is built not to be one.
Powerful actions, hard limits.
Questions about security?
Our team is happy to walk through data handling, hosting and compliance for your rollout.