Skip to content

How SiteMind keeps your data safe.

Your assistant only answers on your websites, only searches your content, and never trains AI models on it. This page explains how that works, what we store and how, and what we do not offer yet.

A visitor’s question passes five checks in order: Your sites only, A limit per visitor, Your workspace only, Is there an answer?, Content kept as content.

What happens to a visitor’s question. Five checks before anything is written.

In this order, on every message, on every plan. The answer that comes out links to the page it came from.

  1. It only answers on your websites

    Each chat request says which website it came from. If that is not one of your domains, or an extra address you have allowed, the request is refused, so nobody can put your assistant on their own site.

  2. Every visitor has a limit

    Each visitor can only send so many messages in a short time. If the limit check itself is unavailable, chat pauses instead of letting unlimited requests through.

  3. It only searches your content

    Every record we store carries your workspace ID, and every search filters on it. Another customer’s assistant cannot find your pages, and yours cannot find theirs.

  4. It checks there is something to answer from

    Before any AI model is called, SiteMind checks whether your content covers the question. If nothing relevant is found, it declines on its own and no model is called at all.

  5. Your pages are treated as reference, not orders

    Your content and the visitor’s words are placed inside marked blocks, and anything that imitates those markers is stripped out first. That makes it much harder for text on a page, or typed into the chat, to take over the assistant.

What we keep instead of your secrets. Never the real thing.

  • Your password

    A bcrypt hash with 12 rounds. We can check a password against it, but never read the password back.

  • API keys

    A SHA-256 hash. You see the key once, when you create it. After that, not even we can show it again.

  • Sign-in sessions

    Access tokens last 15 minutes. Refresh tokens are stored as SHA-256 hashes and replaced each time they are used. If an old one is used again, every session that came from it is signed out.

  • Connected tools and webhooks

    Encrypted with AES-256-GCM, because we need these back to sync your content and sign your webhooks. Each value gets its own random IV.

Sample values, for illustration.

Your content stays yours. What we will and will not do with it.

  • Not used to train AI models

    Your pages, files and your visitors’ conversations are never used to train AI models. Answers are written by Google’s Gemini API under commercial terms that do not allow training on your data.

  • Not sold or shared

    Your content is used to answer your visitors and nothing else. The companies we rely on to run SiteMind are listed on our subprocessors page.

  • Deleted when you ask

    Only the workspace owner can delete a workspace, and they must confirm with their password. Access ends immediately, every member is signed out, and the data is queued for permanent deletion within 30 days, as our privacy policy states.

  • Kept when a trial ends

    If a trial ends without a plan, the assistant pauses and your data stays, so nothing is lost if you come back.

Safe to connect to your systems. Webhooks, AI actions and the API.

  • Signed webhooks

    Every webhook carries an HMAC-SHA256 signature over a timestamp and the body, so your server can reject anything forged or replayed.

  • No calls into private networks

    Before a webhook or AI action is sent, the destination address is looked up and checked. Private and internal addresses are refused, on every attempt.

  • Scoped API keys

    An API key only reaches its own workspace. Keys can be given an expiry date and deleted at any time from the dashboard.

What we do not have yet. Better you hear it here first.

If one of these is a hard requirement for you, tell us early and we will say honestly whether it is coming.

  • SOC 2 or ISO 27001

    We do not hold either certification today. We will fill in your security questionnaire and tell you plainly where the answer is not yet.

  • Single sign-on (SAML)

    You sign in with email and password or with Google. SAML single sign-on is not available.

  • Self-hosting

    SiteMind runs only as a managed cloud service. It cannot be installed on your own servers.

The documents. And where to report a problem.

Found a security issue? Email [email protected] with what you found and how to reproduce it, and give us a chance to fix it before you share it.

Security questions. Answered plainly.

Have a questionnaire to fill in? Send it to us and we will answer it directly.

Email security

No. Your pages, files and visitor conversations are never used to train AI models. Answers are written by Google’s Gemini API under commercial terms that do not allow training on your data.

No. Every record carries your workspace ID and every search filters on it, so one customer’s assistant can never find another customer’s content.

It answers only from your content and links the source it used. If nothing relevant is found, it declines without calling an AI model and can offer to take the visitor’s details instead.

No. Chat requests from websites that are not your domains, or addresses you have allowed, are refused.

Passwords are stored as bcrypt hashes. API keys and refresh tokens are stored as SHA-256 hashes. Tokens for connected tools and webhook secrets, which we need to read back, are encrypted with AES-256-GCM.

Access ends immediately and every member is signed out. The data is then queued for permanent deletion within 30 days, as set out in our privacy policy.

No, not today, and we hold no other formal certification. We will complete your security questionnaire, and our data processing agreement already applies to every account.

Email [email protected] with what you found and how to reproduce it. Please give us a chance to fix it before you share it publicly.

See it answer from your own site. Free for 3 days, no card needed.

No credit card required2-minute automated setupEmbed with one line