Security & compliance

Your data, secured in India

Encryption, Indian data residency and strict tenant isolation — with the outbound-contact controls this kind of platform actually needs.

Last updated: 1 August 2026

BlueAI Chat handles your customers' phone calls, WhatsApp messages and lead lists. This page sets out exactly how that data is protected, where it lives, and what the platform will and will not do.

Data residency

All customer data — conversations, recordings, knowledge bases, contact lists and analytics — is hosted exclusively in Microsoft Azure's Central India region. Your data does not leave India.

Encryption

At rest

Data in Azure PostgreSQL and Azure Storage is encrypted with AES-256, and backups are encrypted too. Selected sensitive fields — including the credentials for channels you connect — carry a further layer of application-level encryption, so they are unreadable even with database access.

In transit

Everything runs over TLS 1.2 or above. The dashboard, the APIs, the chat widget and all webhook traffic are HTTPS-only.

Access controls

  • Tenant isolation — enforced in the database with PostgreSQL Row-Level Security. One account cannot read another's data, even if application code is wrong.
  • Role-based access — Owner, Management and Team Member roles, each scoped. Settings that affect money or compliance are restricted to the owner.
  • Authentication — passwords hashed with bcrypt; JWT session tokens with automatic expiry; SAML single sign-on available.
  • API keys — unique per bot, revocable, and rate-limited to prevent abuse.
  • Audit logging — admin actions are recorded with timestamp, user identity and detail.
  • Webhook verification — inbound telecom and messaging webhooks are signature-verified, so a third party cannot inject fake calls or messages into your account.

AI safety

Scope boundaries

Your AI employee answers from the knowledge you give it. It is configured to decline questions outside that scope rather than improvise, which is what keeps it from inventing a price or a promise.

Guardrails and escalation

You can define restricted topics, custom fallback messages, and the conditions that hand a conversation to a human. Every conversation is reviewable in the dashboard.

Your data is not training data

Your documents, conversations and recordings are never used to train AI models. They stay yours.

Prompt injection defence

The platform defends against jailbreak and prompt-injection attempts so that a caller cannot talk your AI employee out of its instructions.

Compliance

DPDP Act, 2023

The platform is built to support your obligations under India's Digital Personal Data Protection Act. People can request access to, correction of, and deletion of their personal data. See the Privacy Policy.

Outbound contact rules

Because the platform can place calls and send messages at scale, it also carries the controls you need to stay on the right side of TRAI's DND and unsolicited-communication rules and Meta's WhatsApp Business policy — per-category message classification, opt-out handling and campaign-level suspension. Your obligations are set out in the Terms of Service.

Payment security

Payments are processed by Razorpay and Cashfree, both PCI DSS compliant. BlueAI Chat never sees or stores card numbers.

Data retention

Conversations and analytics are retained while the account is active. After cancellation you have 30 days to export, after which business content and conversation data are deleted.

Reporting a vulnerability

Email security@blueaichat.com. Please include enough detail to reproduce the issue. We acknowledge reports within 72 hours and will keep you updated until it is resolved. We will not pursue action against researchers who report in good faith and do not access other customers' data.