Skip to content
Security

Secure by design.

Your tech repair & sales business data is the backbone of your business. We protect it with AES-256 encryption, strict tenant isolation, and SOC 2 certified infrastructure — the same security standards used by leading SaaS platforms.

How does cellbot protect tech repair & sales business data?

cellbot uses AES-256-GCM encryption, tenant isolation, GDPR-supporting privacy controls, layered abuse protection, and timing-safe signature verification — all deployed on enterprise-grade SOC 2 certified infrastructure.

See how these protections support our full feature set, our 11+ integrations, or read our FAQ for common questions.

Active

GDPR-Supporting Controls

Processes and tools for access and erasure requests; DPA available on request

Active

PCI DSS via Stripe

Online card payments use Stripe's PCI DSS Level 1 infrastructure; other payment methods remain with their provider or shop

Active

Encrypted at Rest & In Transit

TLS 1.2+ for data in transit, AES-256 encryption at rest

Active

SOC 2 Certified Infrastructure

All core infrastructure providers hold SOC 2 Type II certification

Planned

Cyber Essentials

UK government-backed certification for cyber security basics

Planned H2 2026

SOC 2 Type I

Organisation-level security, availability, and confidentiality audit

Built-in protection

What security features are built into cellbot?

Every layer of cellbot is built with security in mind — multi-tenant data isolation, 6-layer pricebook protection, HMAC-SHA256 webhook signing, and layered controls on high-risk public workflows.

Multi-Tenant Isolation

Shop-scoped requests validate ownership to isolate each shop's records.

Pricebook Protection

Multi-layer security with entitlement gating, rate limiting, and pagination caps to protect your pricing data.

Authentication & SSO

SOC 2 Type II authentication with multi-factor authentication, social login, role-based access control, and automatic session management.

Rate Limiting & DDoS Protection

Abuse-prone public workflows use layered controls, including authentication, scoped throttling, and edge DDoS protection.

Webhook Verification

Supported inbound webhooks verify provider signatures. Cellbot outbound webhooks use HMAC-SHA256, timing-safe comparison protects signature verification, and replay-sensitive handlers use idempotency guards.

Audit Logging

Key administrative, repair, payment, and customer-record changes are logged with timestamps, user IDs, and context for reviews and incident investigation.

AI governance

Does cellbot use my data to train AI?

No. cellbot does not use your customer conversations, repair records, or pricebook data to train or fine-tune cellbot's AI features.

AI features send only the data needed to fulfil a request to business AI services; shop data stays under your account's controls.

Our business AI services are configured so API data is not used for model training. Processing and retention follow the applicable service terms and our privacy commitments.

AI-generated repair quotes are always sourced from your pricebook. The AI never fabricates prices or invents repair costs — every quote is traceable to a real pricebook entry.

How resilient is cellbot's infrastructure?

cellbot runs on SOC 2 Type II certified infrastructure, with online card payments using Stripe's PCI DSS Level 1 infrastructure.

Edge Hosting

SOC 2 Type II

Edge network, DDoS protection

Realtime Data Platform

SOC 2 Type II

Real-time database infrastructure

Identity Platform

SOC 2 Type II

Authentication & identity

Stripe

PCI DSS Level 1

Payment processing

Data protection

How does cellbot handle my data?

Encryption

Connections use TLS 1.2+ for data in transit. Stored application data is encrypted with AES-256.

Data residency

Application data is stored in SOC 2 Type II certified infrastructure. Edge services run on a global network with automatic regional routing.

Your GDPR rights

We provide processes and tools to support access and erasure requests. Requests are handled under our Privacy Policy and applicable data protection law; a DPA is available on request.

Data retention

Active account data is retained while your account is active. After account closure, retention and deletion follow our Privacy Policy, legal obligations, and operational backup cycles.

Incident response

We follow a structured incident response process: detect, assess, contain, eradicate, recover, and learn. Where required, we notify regulators and affected customers within applicable legal timeframes.

For full details, see our Privacy Policy.

Responsible disclosure

Found a vulnerability?

We take every security report seriously. If you discover a vulnerability, please email security@cellbot.chat. We review reports promptly, prioritise them by severity, and credit reporters unless they prefer anonymity.

Protect your tech repair & tech sales business.

Trust cellbot to protect your tech repair & tech sales business data with GDPR-supporting privacy controls, AES-256 encryption, and tenant isolation.

Cancel any time.