Security & Reliability
Security is a design constraint, not an afterthought
BMAI handles Meta credentials and business data. The platform is built around encryption, approval gates, and strict boundaries around what it will and won't touch.
| Area | Approach |
|---|---|
| Credential storage | Meta access tokens and Page access tokens are encrypted at rest and never logged. |
| Authentication | JWT-based session authentication for every Founder Dashboard and API request. |
| Tenant isolation | Each connected Meta business is isolated by connection scope — one customer's data and history is never visible to another. |
| Approval gates | Any action that reaches Meta requires explicit approval. Autonomous submission is a setting, off by default. |
| Webhook verification | Inbound Meta webhook deliveries are signature-verified and de-duplicated before processing. |
| Communication boundary | BMAI never automates customer-facing messaging (WhatsApp, Messenger). It operates on business assets, not conversations. |
| Official APIs only | Every integration point is Meta's own documented Graph API, Marketing API, or Appeals API — no scraping, no unofficial access. |
| Post-action verification | Writes are independently read back and compared against the expected state before being marked successful. |
Reliability
Built to fail safely
A failing check on one asset or one connected business never blocks monitoring for another. Ambiguous evidence is reported as unknown rather than silently treated as healthy — the platform is designed to be honest about what it doesn't know.