Back to Home
Trust & Security
Encrypted in transit
AES-256 Encrypted

Enterprise-Grade Security

Security is built into every layer of LiveBotIQ — from infrastructure to application design. Your data protection is our top priority.

Last updated: February 1, 2026 · ~8 min read

01

Our Security Philosophy

At LiveBotIQ, security is not an afterthought — it’s built into every layer of our platform. From infrastructure to application design, we follow industry best practices and undergo regular third-party audits to ensure your data is always protected.

Defense in Depth

Multiple layers of security controls

Zero Trust

Verify every request, trust nothing implicitly

Least Privilege

Minimal access rights for every user & service

02

Security Measures

Encryption

  • TLS for all data in transit, HSTS enforced
  • Encryption at rest on managed PostgreSQL
  • Passwords stored using a modern one-way hash
  • Certificates renewed automatically via DNS-01

Infrastructure

  • Managed PostgreSQL with an isolated application host
  • Cloudflare WAF and DDoS mitigation in front of the API
  • Origin firewalled to Cloudflare — direct access refused
  • Forwarded-header validation so client IPs cannot be spoofed

Access Control

  • Role-based access control (owner, admin, agent)
  • Email verification required before first sign-in
  • Server-side sessions with HTTP-only, same-site cookies
  • IP allow and block rules at the application edge

Monitoring

  • Full login audit trail, successful and failed
  • Security event log with configurable retention
  • Dependency vulnerability audit on every deployment
  • Health checks gate each release

Incident Response

  • Documented incident response process
  • Customer notification within 72 hours of a confirmed breach
  • Security events recorded with configurable retention
  • Post-incident review on every confirmed incident

Data Protection

  • Built to GDPR, UK GDPR and India's DPDP Act
  • Data processing agreement available to customers
  • Documented sub-processor list with change notification
  • Access, export and deletion requests supported
03

Certifications & Compliance

CertificationStatus
GDPR & UK GDPRIn progress
India DPDP ActIn progress
PCI DSSHandled by provider
SOC 2 Type IINot certified
04

Application Security

Dependency vulnerability audit on every deployment
Application firewall with attack-pattern detection
Framework-level input validation and output encoding
Rate limiting across the authentication surface
Cloudflare Turnstile on signup, password reset and repeated failed logins
Email verification required before an account can be used
05

Data Handling

4 hrs

RTO

Recovery Time Objective

1 hr

RPO

Recovery Point Objective

30 days

Deletion

Data permanently removed

90 days

Backup Purge

Backups with deleted data

AData Isolation

Each customer’s data is logically isolated within our infrastructure. Enterprise customers can opt for dedicated database instances for additional isolation.

BBackup & Recovery

Automated daily backups with point-in-time recovery
Backups encrypted & stored in geographically separate regions
Recovery Time Objective (RTO): 4 hours
Recovery Point Objective (RPO): 1 hour

CData Deletion

When you delete data or close your account, we permanently remove your data within 30 days. Backups containing deleted data are purged within 90 days.

06

Employee Security

Background checks for all employees
Mandatory security awareness training
Principle of least privilege access
Quarterly access reviews & credential rotation
Secure development training for engineering teams
07

Bug Bounty Program

We maintain a responsible disclosure program. If you discover a security vulnerability, report it to security@livebotiq.com.

We commit to the following response timeline:

24h

Acknowledge your report within 24 hours

48h

Provide an estimated timeline for resolution

Ongoing

Keep you informed of our progress

On fix

Recognize your contribution (with permission)

08

Contact Our Security Team

For security-related questions, to report a vulnerability, or to request our data processing agreement:

PGP Key

Available upon request for encrypted communications