Security
Last updated: August 2026
1. Data Protection
We use industry-standard tools (Supabase, hosted infrastructure with TLS encryption) to protect client data in transit and at rest across the systems we build and operate.
2. Access Control
Access to client systems, API keys, and credentials is limited to personnel directly involved in delivering the engagement, and stored using secure secrets management rather than plaintext files.
3. Third-Party Integrations
Our automation systems connect to platforms such as OpenAI, VAPI, WhatsApp Business API, and CRM tools using authenticated, scoped API access — never shared or hardcoded credentials in client-facing code.
4. Client Data Ownership
Clients retain ownership of their business data processed through Automa8-built systems. We do not use client data to train external models without explicit written consent.
5. Reporting a Concern
If you discover a security vulnerability related to a system we've built, please report it to hello@automa8.co.