Skip to content

Draft, not yet live. Pending legal review and technical verification.

Bonfire
For ChurchesFor Businesses
How It WorksPricing
BlogResource HubTrust CenterHelp Center
About
Log In

Security Overview

Effective Date: September 1, 2026 · Last updated September 1, 2026

On this page

    Your organization's knowledge powers every conversation, so we protect it accordingly. Below are the technical and organizational controls that keep Bonfire safe and resilient.

    No third-party model training

    Provider API terms do not permit training their models on your content or conversations. Bonfire does not use customer content or conversation data to train third-party foundation models.

    Workspace isolation

    Public agents never see internal knowledge bases.

    1. Infrastructure

    • Bonfire runs on VERIFY: Supabase / AWS / GCP / Vercel in U.S. data centers operated by providers holding SOC 2 Type II and ISO 27001 certifications.
    • Environments are separated (production vs. development); production access is restricted to authorized engineers.
    • VERIFY: network controls, WAF/DDoS protections via hosting provider.

    2. Encryption

    • All data in transit is encrypted via TLS 1.2+.
    • Data at rest is encrypted using AES-256 VERIFY provider-level encryption.
    • Secrets and credentials are stored in managed secret stores, never in code. VERIFY

    3. Workspace Isolation and Access Control

    • Each customer organization's workspace, knowledge bases, and conversation data are logically isolated; agents can only access the content explicitly assigned to them.
    • Public agents never see internal knowledge bases: permissions are enforced at the knowledge-base level (internal vs. public audiences).
    • Role-based access within workspaces (admin, staff, and viewer roles) VERIFY role names.
    • Bonfire staff access to customer data is limited to support, troubleshooting, safety, and abuse prevention, logged and reviewed. VERIFY logging

    4. AI Model Providers

    Responses are generated via API access to leading model providers:

    AI model providers used to generate responses
    ProviderRole
    OpenAIResponse generation
    AnthropicResponse generation
    GoogleResponse generation
    • Provider API terms do not permit training their models on your content or conversations.
    • Bonfire does not use customer content or conversation data to train third-party foundation models.
    • Model routing and reasoning levels are configurable per workspace VERIFY, and providers can be swapped as the frontier moves, so customers are not locked to one vendor's roadmap.

    5. Data Handling

    • Customers own their content and conversation data; admins control retention within plan settings VERIFY defaults.
    • Exports: knowledge bases and content are exportable; on termination, exports are available for 30 days before deletion per the retention schedule align with Terms.
    • Analytics pipelines receive usage events, not raw conversation payloads. VERIFY, this mirrors the LIVE AI claim "no third-party analytics ever touches raw conversational payloads."

    6. Application Security

    • Code review required before production deploys; dependency and vulnerability scanning VERIFY tooling.
    • Least-privilege service accounts between components. VERIFY
    • Regular backups with point-in-time recovery VERIFY RPO/RTO; restores tested VERIFY cadence.

    7. Incident Response

    • Security incidents are triaged by the engineering team with a documented runbook VERIFY / create one if missing.
    • Customers affected by a breach are notified without undue delay, consistent with applicable law and our Terms.
    • Status and maintenance notices are communicated via status page / email - VERIFY.

    8. Responsible Disclosure

    We welcome good-faith security research. Report suspected vulnerabilities to security@heybonfire.com VERIFY alias exists; create it. Do not access data that is not yours, degrade the service, or disclose publicly before we have had a reasonable window to remediate. We will acknowledge reports within 3 business days.

    9. Compliance Posture

    • Bonfire is not yet SOC 2 or ISO 27001 certified; we align our controls to those frameworks and to the practices of our certified infrastructure providers. (Honest posture, same approach LIVE AI took publicly.)
    • CCPA/CPRA: see our Privacy Policy for consumer rights and how we honor them.
    • HIPAA: Bonfire is not a HIPAA covered entity or business associate by default; do not submit PHI without a written agreement.
    • DPAs available for customers who require them. Prepare standard DPA.

    10. Customer Controls (your side of the shared model)

    • Assign content deliberately: public agents get public content only.
    • Use guidance (voice, boundaries, safety, operations) to constrain agent behavior.
    • Configure human handoff and crisis routing for care contexts.
    • Manage admin access and offboard departed staff promptly.
    • Tell your end users how conversations are stored and reviewed (we provide notice links; your policies do the rest).

    Questions: support@heybonfire.com

    Related documents

    Terms of ServiceLast updated September 1, 2026Privacy PolicyLast updated September 1, 2026Partner Program AgreementAvailable on request · partners@heybonfire.com

    Questions about this document? Email support@heybonfire.com.

    Bonfire

    Light more fires.

    PRODUCT

    • How It Works
    • Pricing
    • Demo
    • Integrations

    SOLUTIONS

    • For Churches
    • For Businesses
    • Partners
    • Use Cases

    RESOURCES

    • Blog
    • Resource Hub
    • Case Studies
    • Help Center

    COMPANY

    • About
    • Careers
    • Contact

    LEGAL

    • Terms of Service
    • Privacy Policy
    • Security
    • Trust Center

    2026 Bonfire. All rights reserved.