bots4.me

Security

At BOTS4.me, security isn’t just a feature—it’s fundamental to everything we do. Our business depends on protecting your data, which is why we’ve built our platform with comprehensive security measures that meet and exceed industry standards for business automation services.

End-to-End Encryption
Two-Factor Authentication
Privacy First Design
Zero-Persistence Processing
Zero-Touch Disk
Zero Security Incidents Over 2 years of operation

🔐 Secure Quick Connect (OAuth) Explained

Most modern services (Gmail, Outlook, Google Drive, OneDrive, Dropbox, Box, Slack) support “OAuth” – a security standard where you log in directly on THEIR website, never giving us your password. They confirm your identity and give us a special permission key that only does what you approved.

For services that don’t support OAuth yet, we use RSA-2048 encryption – the same technology banks use to protect credentials. Either way, you have complete control from your /bots dashboard.

Works with 50+ services: Gmail, Outlook, Google Drive, OneDrive, Dropbox, Box, Slack, and more

Multi-Layer Encryption

We implement industry-standard encryption protocols including enterprise cloud encryption services and RSA key pairs to protect your data both in transit and at rest.

Isolated Infrastructure

Your automation processes run on dedicated, protected servers with strict access controls and comprehensive security monitoring to prevent unauthorized access.

Privacy by Design

Sensitive information is encrypted at the point of submission and remains encrypted throughout our systems. Only authorized processes can access your data when needed.

Transparent Practices

We maintain clear data handling policies and provide comprehensive documentation about our security practices, so you know exactly how your information is protected.

Secure Quick Connect (OAuth 2.0) – The Most Secure Option

For major providers like Gmail, Outlook, Google Drive, Dropbox, OneDrive, Box, and Slack, we support industry-standard Secure Quick Connect (OAuth 2.0) – the same secure method used by millions of applications worldwide.

What is OAuth and Why It’s Better

No Password Storage: You never enter your email or cloud storage password on our website. Instead, you log in directly on Google, Microsoft, or Dropbox’s own secure login page.
Limited, Listed Permissions: OAuth gives us only the specific scopes you approve on the provider’s consent screen. For Microsoft 365 / Outlook, that means scopes like IMAP.AccessAsUser.All, Mail.ReadWrite, MailboxSettings.ReadWrite and (for Mail2CLOUD) the narrow Files.ReadWrite.AppFolder scope that can only see a single folder we create. For Gmail, scopes like https://mail.google.com/ (required by Google for IMAP/SMTP over OAuth), gmail.labels, gmail.settings.basic and (for Mail2CLOUD on Google Drive) drive.file, which can only see files our app created. The full per-scope justification is in our Privacy Policy.
Revoke Anytime: You can instantly revoke BOTS4.me access from your Google or Microsoft account settings without changing passwords or contacting support.
Industry Standard: OAuth 2.0 is used by thousands of trusted applications and is the recommended authentication method by Google, Microsoft, and other major providers.

How OAuth Login Works

1

Click “Connect with Google/Microsoft”

2

Redirected to provider’s secure login

3

Approve permissions on their site

4

Secure token sent to BOTS4.me

5

Token encrypted & stored securely

OAuth vs. Password: You Choose

We give you the choice between OAuth (recommended for supported providers) and traditional app passwords/API keys. Both are secure – OAuth just eliminates password storage entirely. For services that don’t support OAuth, we use RSA-2048 encryption to protect your credentials with the same bank-level security.

What We Never Do With OAuth-Granted Access

  • We never use your email content, contacts, attachments or any Google/Microsoft user data to build, train or improve generalised or third-party AI/ML models. Models are tuned on your account’s own data only.
  • We never sell your data, share it with advertising networks, or use it to serve targeted ads.
  • We never read mail or open attachments for human review except where strictly required to deliver a feature you activated, or where you explicitly request support troubleshooting on a specific message.
  • We never permanently delete mail, files or folders that we did not create.
  • We never transfer OAuth tokens to any party outside our infrastructure, except to the issuing provider (Microsoft or Google) when we exchange or refresh them.
  • We comply with the Google API Services User Data Policy, including the Limited Use requirements.

How We Protect Your Business Data

When you trust BOTS4.me with access to your ERP and email systems, we take that responsibility seriously. Our security architecture is designed specifically for the unique challenges of business process automation:

Secure Data Transmission

Every connection between your systems and our platform is protected:

Modern TLS encryption ensures all data in transit is protected from interception
Enterprise secure key management with automated rotation and hardened storage vault
API authentication using industry-standard protocols and secure tokens

Zero-Disk Decrypted Data Protection

Our most rigorous security practice – even while processing, we NEVER save anything in decrypted form to disk:

Memory-only processing – all operations happen exclusively in RAM, decrypted data exists only during active processing (seconds to minutes)
No temporary files – no cache, no logs with sensitive data, nothing persists if servers lose power
7-day automatic deletion of processed files and temporary data, 14-day cleanup for operational data
Encrypted at rest – your data is ALWAYS encrypted when stored, even our engineers cannot access it
Immediate removal upon customer request with verification

RSA-2048 Encryption Architecture

How we protect your credentials using the same technology banks use:

Instant encryption – when you save credentials in /bots, they’re immediately encrypted with your unique public key
Separated key storage – encryption keys stored separately from encrypted data in different secure locations
Processing flow – data decrypted in memory only, processed, then results encrypted again
Zero-knowledge architecture – we cannot read your credentials even if we wanted to

Access Control & Authentication

Multiple layers of security protect access to your systems:

Secure Quick Connect (OAuth 2.0) for all supported services – Gmail, Outlook, Google Drive, OneDrive, Dropbox, Box, Slack, and 50+ others. Your password NEVER touches our servers. For legacy systems: RSA-2048 encrypted credentials with the same protection banks use.
Mandatory two-factor authentication for all access points
Custom-developed protection system against common attack vectors
Comprehensive activity logging for security monitoring and auditing

Security Standards Comparison

See how our security measures compare to typical automation services:

← Scroll horizontally to view all columns →
Security Feature Basic Services Industry Standard BOTS4.me
Data Encryption Basic SSL TLS + Storage Encryption End-to-End Encryption
Authentication Password Only Optional 2FA Mandatory 2FA
Data Retention Indefinite 90-180 days 7-day Auto-deletion
Processing Method Standard Storage Encrypted Storage Zero-disk Processing
Access Monitoring Basic Logs Activity Tracking Comprehensive Auditing
Infrastructure Shared Servers Virtual Isolation Dedicated Servers (Premium) / Isolated Containers (Standard)

Data Privacy & Compliance

We’ve designed our platform with privacy at its core, ensuring your business data is handled with the utmost care and in compliance with data protection best practices:

  • Minimal Data Collection: We only process the data necessary for your specific automation needs – nothing more.
  • Transparent Data Handling: Clear documentation of what data we access, how it’s processed, and when it’s deleted.
  • User Control: You maintain full control over your data with the ability to request immediate deletion at any time.
  • Encrypted Form Submissions: Sensitive information entered during onboarding is encrypted immediately upon submission.
  • Separate Key Management: Encryption keys are stored separately from encrypted data for enhanced security.
  • No Unnecessary Storage: We don’t store any data we don’t actively need for your automation processes.

Operating Without AI

Some organisations are not permitted to process business data with AI — banks and insurers under internal policy, public-sector bodies under procurement rules, and suppliers bound by a customer contract. Most of our automation was built on rules long before it was given AI, and it still runs that way.

  • Five bots contain no AI at all: AutoERP, AutoCASH, AutoSTOCK, AutoPURCHASE and Mail2CLOUD. There is no switch, because there is nothing to switch off.
  • Four bots have an AI Mode switch: AutoSPAM, Mail2ERP, Pay2ERP and Supplier2ERP. Set to Off, no language model is called and no content is sent to any AI provider. These bots still use statistical matching, which runs on your own server and never transmits your data.
  • Two bots cannot work without AI: ClientFACTORY and Mail2KNOW generate written text. We say so here rather than let you find out after you buy.
  • Off means off: setting AI Mode to Off takes effect on the next run and overrides every other setting, including Demo Mode.
  • Evidence for your file: on request we will send you a report generated from your own installation, listing the resolved AI mode of every bot on your account.

Demo Mode — Your Safety Switch

Demo Mode is a built-in safety control that lets you verify exactly what the bot would do before enabling full automation. It is enabled by default for all new accounts, ensuring a safe starting point.

Safe by default — Demo Mode is ON for every new account. No data is written to your ERP or cloud systems until you explicitly choose to allow it.
Proof before automation — every app must complete at least one demo run and email you a report of exactly what it WOULD have done before Demo Mode can be switched off. The first run is always a demo — nothing is ever written without your informed consent. More about Demo Mode →
One-click safety — you can switch Demo Mode back ON at any time from the Control tab on your /bots dashboard, effective immediately. Switching Demo Mode OFF unlocks only after your first demo run report — so live writes can never be enabled by accident.
Non-destructive preview — With Demo Mode ON, the system continues to monitor, analyze, and report, but will not write any changes. You can see exactly what would happen without risk.
Always available — Even with full access configured, Demo Mode gives you a safety switch to prevent unintended changes at any time. Perfect for testing, audits, or onboarding new team members.

Infrastructure Security

Our technical infrastructure is built with security as a fundamental requirement:

Enterprise cloud infrastructure with institutional-grade security configurations
Regular security updates and proactive vulnerability management
Isolated processing environments for each customer’s automation tasks
Automated security monitoring to detect and prevent suspicious activities
Secure development practices with code review and security testing
Regular backup procedures with encrypted storage and secure recovery

Server Architecture & Isolation

We’ve implemented intelligent server assignment to optimize both security and performance:

Enterprise/Premium Clients – dedicated isolated servers with resources exclusively for your needs, no sharing with other clients, complete isolation
Standard Clients – “pool” servers with harmonized resource allocation, complete isolation between clients (separate containers), same encryption and security standards
All Tiers Include – end-to-end encryption, zero-disk decrypted data policy, automatic data cleanup (7/14 days), 24/7 security monitoring
“We’ve been working with BOTS4.me for over two years now, processing thousands of emails and transactions. In all that time, we haven’t experienced a single security incident or service interruption. Their commitment to data protection and reliable service has been consistent from day one.”
MP
Miroslav Petras
Managing Director, IMP Kontakt

💼 Growing Startup, Professional Standards

We’re a growing startup committed to professional-grade security practices. While we’re working toward formal certifications (SOC 2, ISO 27001), we’ve already built our platform around the core security practices these frameworks emphasize. Our zero-disk decrypted processing, automatic data deletion, and Secure Quick Connect (OAuth) approach demonstrate our commitment to your data protection from day one.

Built on a Foundation of Trust

We understand that automation requires access to critical business systems. That’s why we’ve invested heavily in security infrastructure and practices that protect your data while enabling powerful automation. Let’s discuss how our security measures align with your business requirements.

Ask us if you’re still concerned.