MagizAI
Security & trust

Safe by design, private by default.

MagizAI is built multi-tenant with encryption, strict guardrails, and hard limits on what the AI can see and do. Here's how we keep your data and your customers safe.

Encrypted credentials

Every connector token and AI key is stored encrypted, per tenant, and never returned by the API.

Bring your own key

Use your own AI provider keys so prompts and data flow through your account, not a shared one.

SSRF-hardened crawling

Training fetches validate resolved IPs, block private ranges, pin DNS, and cap size, no server-side request forgery.

Strict guardrails

No hallucinated facts or prices, stay-on-topic enforcement, and graceful fallback on every AI call.

Multi-tenant isolation

Each workspace is isolated; suspended tenants are locked out of app, API and portal by middleware.

Metered & auditable

Every AI call is logged with tokens and cost, and sensitive actions carry a full audit trail.

Card numbers never stored

Visitors paste card numbers into chat whatever you ask them not to. We detect and mask them before the first write, so they never reach the database, the transcript, or your AI provider. Only the last four survive.

Defended against poisoned pages

A page you train on could contain instructions aimed at your bot. Retrieved content is stripped of instruction-shaped text and fenced as data, so a crawled page can inform an answer but never issue an order.

Data requests, handled

Export or erase everything held about one visitor: transcripts, contact details, browsing profile and remembered facts. Conversations are deleted, not anonymised, because a transcript still names the person. Every erasure is audit-logged.

Accessible to everyone

The widget is keyboard-navigable, screen-reader-labelled and closes on Escape, with visible focus throughout. Chat widgets are a common target of accessibility complaints; ours is built not to be one.

The Auto-Pilot promise

Powerful actions, hard limits.

Never types passwords, OTPs or card details.
Confirms before any risky or destructive action.
Grounded only in your knowledge base.
Client-side redaction of sensitive fields.

Questions about security?

Our team is happy to walk through data handling, hosting and compliance for your rollout.

Contact our team See pricing