You trust us with sensitive financial data. We design for it.
Subscriber Bot handles identity, payments, and contracts. Below is how security and privacy are being built into the foundations — and where we're heading on compliance. No claims we can't back up.
How we design for security
Subscriber Bot is being built on the Burdenoff platform, which provides the security backbone — encryption, RBAC, multi-tenancy, and audit — that every edition inherits.
Encryption at rest
Sensitive credentials, payment-source references, and contract documents are designed to be encrypted at rest, with secrets unwrapped only at runtime through a managed secrets store — never stored or shown in plaintext.
TLS in transit
All traffic between your client and Subscriber Bot is encrypted in transit over HTTPS. Connections to external providers and adapters run over secure channels.
Role-based access control
Authorization is enforced at the API edge before requests reach backend services, so your data is only accessible to identities and roles you authorize.
Tenant isolation
Multi-tenant isolation keeps individuals and organizations logically separated end-to-end. Enterprise customers can request dedicated tenancy.
Immutable audit log
Every action — including autonomous AI changes — is designed to be captured (actor, resource, before/after) so automation stays auditable and reversible.
Universal Consent
You set newsletter, marketing, and privacy preferences once and providers inherit them. Your Universal Subscription Identity keeps preferences and consent under your control.
What can Subscriber Bot see — and how is AI handled?
Because Subscriber Bot reads inboxes and statements to discover subscriptions, it's fair to ask exactly how that data is treated.
Connected sources. Connections to your inbox and payment sources are designed to be read-only where possible and scoped to the minimum needed to detect recurring relationships. You can disconnect a source at any time.
AI processing. The AI Subscription Brain is designed to reason over your relationship graph to surface insights and recommended actions. Your private subscription and financial data is processed to serve you — it is not intended to be sold or used to train third-party models.
Autonomous actions. Any action the AI takes happens within policies you define, is recorded in the immutable audit log, and is reversible. High-stakes actions can require human-in-the-loop approval.
Compliance & roadmap
We name what we're working toward and what's in flight. Buyers should never have to guess.
Reporting a vulnerability
Found something? We want to hear from you. Coordinated disclosure with a same-business-day acknowledgement.