Security · Policy before automation

Security and policy-aware automation.

AI MessageBot separates AI reply generation from permission to send. It can automatically deliver eligible replies, but only after the current conversation passes configured policy checks.

Safety model Policy before automation

The answer can be intelligent. The send decision stays rule-bound.

When every required condition passes, automatic delivery continues without a manual Send click. The policy is checked again immediately before the message leaves.

  • Consent-awareThe current opt-in state remains part of every autonomous send decision.
  • Window-awareOrdinary outbound replies require an open WhatsApp customer-service window.
  • Human-overridableA team member can pause, review, edit, or take over at any time.

Designed to re-check policy before deliveryAvailable checks are evaluated against the current conversation state and deployment configuration.

Every required condition must passCurrent conversation

Live check

Consent-aware

Opted in

Window-aware

Open

Human-overridable

Passed

The applicable service window is open

Passed

Global automation is enabled

Passed

Chat automation is enabled

Passed

Chat is not paused

Passed

AI provider is ready

Passed
Send policyPolicy is re-checked before delivery
Allowed
!

When one required condition changes

Automatic delivery stops before sending when any required condition fails.

ConsentNot opted in
ResultSend blockedHuman follow-up required

Deployment Controlled central architecture

Deployment and security boundaries

The intended architecture keeps sensitive operations central and limits client access to the product interface over HTTPS.

Web app / PWAPhone, tablet and browser access

Desktop clientWindows, macOS and Linux packaging

Central single-node serviceAI MessageBot backendAuthentication · CRM · policy · AI orchestration

  • Server-side secrets
  • JSON data + backups
  • Audit events
W

WhatsApp BusinessCloud API

Configured AIGemini, NVIDIA, or disabled

01

One data owner

JSON persistence is designed for one application process on one data directory, not competing multi-process writers.

02

Secrets stay server-side

Cloud API credentials, AI keys, application secrets, backups, and customer data do not belong in client bundles.

03

Distribution follows readiness

Mobile web access and desktop packaging remain separate from signed installers, update feeds, and public store releases.

Central self-hosted backend
HTTPS client access
Server-side secrets
JSON data plus backups
Audit events
Account roles
HttpOnly cookies
SameSite=Strict
CSRF protection
Rate limiting
Chat access controls
No QR login
No personal WhatsApp sessions
Single-node persistence model

Responsible disclosure

Report potential security vulnerabilities to security@ai-messagebot.app. Do not send passwords, API keys, WhatsApp tokens, private keys, customer data or chat exports through general support channels.

security@ai-messagebot.app