Security
At BOTS4.me, security isn’t just a feature—it’s fundamental to everything we do. Our business depends on protecting your data, which is why we’ve built our platform with comprehensive security measures that meet and exceed industry standards for business automation services.
🔐 Secure Quick Connect (OAuth) Explained
Most modern services (Gmail, Outlook, Google Drive, OneDrive, Dropbox, Box, Slack) support “OAuth” – a security standard where you log in directly on THEIR website, never giving us your password. They confirm your identity and give us a special permission key that only does what you approved.
For services that don’t support OAuth yet, we use RSA-2048 encryption – the same technology banks use to protect credentials. Either way, you have complete control from your /bots dashboard.
Multi-Layer Encryption
We implement industry-standard encryption protocols including enterprise cloud encryption services and RSA key pairs to protect your data both in transit and at rest.
Isolated Infrastructure
Your automation processes run on dedicated, protected servers with strict access controls and comprehensive security monitoring to prevent unauthorized access.
Privacy by Design
Sensitive information is encrypted at the point of submission and remains encrypted throughout our systems. Only authorized processes can access your data when needed.
Transparent Practices
We maintain clear data handling policies and provide comprehensive documentation about our security practices, so you know exactly how your information is protected.
Secure Quick Connect (OAuth 2.0) – The Most Secure Option
For major providers like Gmail, Outlook, Google Drive, Dropbox, OneDrive, Box, and Slack, we support industry-standard Secure Quick Connect (OAuth 2.0) – the same secure method used by millions of applications worldwide.
What is OAuth and Why It’s Better
IMAP.AccessAsUser.All, Mail.ReadWrite,
MailboxSettings.ReadWrite and (for Mail2CLOUD) the narrow Files.ReadWrite.AppFolder scope that can only see a single
folder we create. For Gmail, scopes like https://mail.google.com/ (required by Google for IMAP/SMTP over OAuth),
gmail.labels, gmail.settings.basic and (for Mail2CLOUD on Google Drive) drive.file,
which can only see files our app created. The full per-scope justification is in our
Privacy Policy.
How OAuth Login Works
Click “Connect with Google/Microsoft”
Redirected to provider’s secure login
Approve permissions on their site
Secure token sent to BOTS4.me
Token encrypted & stored securely
OAuth vs. Password: You Choose
We give you the choice between OAuth (recommended for supported providers) and traditional app passwords/API keys. Both are secure – OAuth just eliminates password storage entirely. For services that don’t support OAuth, we use RSA-2048 encryption to protect your credentials with the same bank-level security.
What We Never Do With OAuth-Granted Access
- We never use your email content, contacts, attachments or any Google/Microsoft user data to build, train or improve generalised or third-party AI/ML models. Models are tuned on your account’s own data only.
- We never sell your data, share it with advertising networks, or use it to serve targeted ads.
- We never read mail or open attachments for human review except where strictly required to deliver a feature you activated, or where you explicitly request support troubleshooting on a specific message.
- We never permanently delete mail, files or folders that we did not create.
- We never transfer OAuth tokens to any party outside our infrastructure, except to the issuing provider (Microsoft or Google) when we exchange or refresh them.
- We comply with the Google API Services User Data Policy, including the Limited Use requirements.
How We Protect Your Business Data
When you trust BOTS4.me with access to your ERP and email systems, we take that responsibility seriously. Our security architecture is designed specifically for the unique challenges of business process automation:
Secure Data Transmission
Every connection between your systems and our platform is protected:
Zero-Disk Decrypted Data Protection
Our most rigorous security practice – even while processing, we NEVER save anything in decrypted form to disk:
RSA-2048 Encryption Architecture
How we protect your credentials using the same technology banks use:
Access Control & Authentication
Multiple layers of security protect access to your systems:
Security Standards Comparison
See how our security measures compare to typical automation services:
| Security Feature | Basic Services | Industry Standard | BOTS4.me |
|---|---|---|---|
| Data Encryption | Basic SSL | TLS + Storage Encryption | End-to-End Encryption |
| Authentication | Password Only | Optional 2FA | Mandatory 2FA |
| Data Retention | Indefinite | 90-180 days | 7-day Auto-deletion |
| Processing Method | Standard Storage | Encrypted Storage | Zero-disk Processing |
| Access Monitoring | Basic Logs | Activity Tracking | Comprehensive Auditing |
| Infrastructure | Shared Servers | Virtual Isolation | Dedicated Servers (Premium) / Isolated Containers (Standard) |
Data Privacy & Compliance
We’ve designed our platform with privacy at its core, ensuring your business data is handled with the utmost care and in compliance with data protection best practices:
- Minimal Data Collection: We only process the data necessary for your specific automation needs – nothing more.
- Transparent Data Handling: Clear documentation of what data we access, how it’s processed, and when it’s deleted.
- User Control: You maintain full control over your data with the ability to request immediate deletion at any time.
- Encrypted Form Submissions: Sensitive information entered during onboarding is encrypted immediately upon submission.
- Separate Key Management: Encryption keys are stored separately from encrypted data for enhanced security.
- No Unnecessary Storage: We don’t store any data we don’t actively need for your automation processes.
Operating Without AI
Some organisations are not permitted to process business data with AI — banks and insurers under internal policy, public-sector bodies under procurement rules, and suppliers bound by a customer contract. Most of our automation was built on rules long before it was given AI, and it still runs that way.
- Five bots contain no AI at all: AutoERP, AutoCASH, AutoSTOCK, AutoPURCHASE and Mail2CLOUD. There is no switch, because there is nothing to switch off.
- Four bots have an AI Mode switch: AutoSPAM, Mail2ERP, Pay2ERP and Supplier2ERP. Set to Off, no language model is called and no content is sent to any AI provider. These bots still use statistical matching, which runs on your own server and never transmits your data.
- Two bots cannot work without AI: ClientFACTORY and Mail2KNOW generate written text. We say so here rather than let you find out after you buy.
- Off means off: setting AI Mode to Off takes effect on the next run and overrides every other setting, including Demo Mode.
- Evidence for your file: on request we will send you a report generated from your own installation, listing the resolved AI mode of every bot on your account.
Demo Mode — Your Safety Switch
Demo Mode is a built-in safety control that lets you verify exactly what the bot would do before enabling full automation. It is enabled by default for all new accounts, ensuring a safe starting point.
Infrastructure Security
Our technical infrastructure is built with security as a fundamental requirement:
Server Architecture & Isolation
We’ve implemented intelligent server assignment to optimize both security and performance:
💼 Growing Startup, Professional Standards
We’re a growing startup committed to professional-grade security practices. While we’re working toward formal certifications (SOC 2, ISO 27001), we’ve already built our platform around the core security practices these frameworks emphasize. Our zero-disk decrypted processing, automatic data deletion, and Secure Quick Connect (OAuth) approach demonstrate our commitment to your data protection from day one.
Built on a Foundation of Trust
We understand that automation requires access to critical business systems. That’s why we’ve invested heavily in security infrastructure and practices that protect your data while enabling powerful automation. Let’s discuss how our security measures align with your business requirements.
Ask us if you’re still concerned.