Security
Security at nullbot
Last updated: July 18, 2026 · Version 1.0
The security of your data and your customers' data is at the heart of nullbot's design. This document explains, in plain language, how nullbot protects your business. It presents our general approach; it deliberately discloses no technical detail that could be misused.
This document is for informational purposes and does not replace the contractual commitments set out in the terms of use, the terms of sale and the personal data processing agreement, nor the privacy policy.
1. Our approach: security by architecture
nullbot is not an online platform where you would upload your data. It is software that installs and runs on your company's own computers. This architectural choice is our first line of defense: the best-protected data is data that never leaves your environment.
In concrete terms, the work of your agents — reading emails, analyzing documents, executing tools, AI model reasoning — takes place locally, on your machine. Our servers are not designed to see or host this content.
2. Where your data lives
The data handled by your agents (messages, customer records, documents, task results) is stored on the machine where nullbot is installed. It does not pass through, and is not retained in, a central database operated by nullbot.
The servers nullbot operates serve a deliberately narrow scope: managing your license and your account. This minimal footprint mechanically limits the exposed surface: there is no large central warehouse of your data to target.
3. Your keys and access
nullbot works with your own access credentials to the artificial intelligence models and tools you connect. These credentials are stored on your machine, under your control.
nullbot does not centralize your keys and does not make them a mandatory server-side passthrough. You retain the ability to rotate or revoke them at any time with the providers concerned.
4. No infrastructure shared between clients
Each nullbot installation is self-contained. There is no shared database in which your information would sit alongside that of other client companies. There is therefore no “neighbor” able to access your data as a result of a tenant-isolation error on a shared platform.
This separation by design eliminates an entire category of risks specific to shared services.
5. Segregation between your companies
If you manage several organizations from nullbot, their data, their agent teams, and their settings are kept separate. Information attached to one company is not visible from another: each scope remains distinct.
6. Encryption of communications
Network exchanges between nullbot, artificial intelligence services, and the tools you connect travel over connections encrypted to standard web practices (HTTPS/TLS). At rest, your data remains on your machine and benefits from the protections provided by your operating system and by the measures you apply to your own machines.
7. Least privilege and human oversight
nullbot applies the principle of least privilege: each agent only has the tools and access you explicitly grant it. An agent cannot act beyond what you have authorized.
Moreover, governance stays in your hands. Depending on the rules you define, sensitive actions can require human validation before being executed. You remain the decision-maker for the operations that matter, and you can track your agents' activity.
8. Security Updates
nullbot is maintained on an ongoing basis. The application includes an update mechanism enabling improvements and security fixes to be rolled out quickly. We recommend keeping your installation up to date so you can benefit from the latest protections.
9. Your responsibilities
Because nullbot runs on your machines and with your access credentials, part of security relies on measures that you are best placed to apply. We invite you in particular to:
- protect access to the computers on which nullbot is installed (locked session, disk encryption, separate user accounts);
- restrict the credentials and keys you connect to controlled use, and renew them if you suspect a compromise;
- enable, where possible, multi-factor authentication on the accounts and tools connected to your agents;
- grant each agent only the access strictly necessary for its mission;
- keep nullbot, your operating system, and your tools up to date.
Security is a shared responsibility: we design the software to protect you, and these best practices reinforce that protection within your environment.
10. Reporting a vulnerability
We welcome reports from security researchers and users. If you believe you have discovered a vulnerability, please disclose it to us responsibly, allowing us a reasonable amount of time to analyze and fix it before any public disclosure.
You may write to us at contact@nullbot.ai, or, failing that, by post to: MARA LABS — Security — 41 rue Jacquemars Giélée, 59800 Lille, France.
Please describe the issue precisely along with how to reproduce it, and avoid accessing data that does not belong to you or degrading the service as part of your research. We are committed to reviewing every good-faith report with diligence.
11. Transparency and limitations
No software can promise absolute security, and we refuse to claim otherwise. Our commitment is twofold: to design nullbot to reduce risk through its very architecture, and to remain transparent with you.
For the same reason, this document describes our approach without disclosing technical details that could help an attacker. Client companies with in-depth security requirements are welcome to contact us for a dedicated discussion.