Security & Reliability

Security is a design constraint, not an afterthought

BMAI handles Meta credentials and business data. The platform is built around encryption, approval gates, and strict boundaries around what it will and won't touch.

AreaApproach
Credential storageMeta access tokens and Page access tokens are encrypted at rest and never logged.
AuthenticationJWT-based session authentication for every Founder Dashboard and API request.
Tenant isolationEach connected Meta business is isolated by connection scope — one customer's data and history is never visible to another.
Approval gatesAny action that reaches Meta requires explicit approval. Autonomous submission is a setting, off by default.
Webhook verificationInbound Meta webhook deliveries are signature-verified and de-duplicated before processing.
Communication boundaryBMAI never automates customer-facing messaging (WhatsApp, Messenger). It operates on business assets, not conversations.
Official APIs onlyEvery integration point is Meta's own documented Graph API, Marketing API, or Appeals API — no scraping, no unofficial access.
Post-action verificationWrites are independently read back and compared against the expected state before being marked successful.
Reliability

Built to fail safely

A failing check on one asset or one connected business never blocks monitoring for another. Ambiguous evidence is reported as unknown rather than silently treated as healthy — the platform is designed to be honest about what it doesn't know.