Security & data posture
An AI on your storefront that can't go off-script.
Bespoke Seb is built so a luxury house can put an AI associate in front of customers without losing control — it can't invent a product, a price, or a promise, and every sensitive action is logged. Here is exactly what's in place, and what's on the way.
Built secure by design
Trust earned by architecture, not by promise.
No hallucinated commerce
The associate can only surface pieces a live catalogue query returned in that conversation. Prices and policies come only from your systems — it cannot invent a product, a price, or a promise.
Human approval gate
Catalogue and knowledge changes are staged for review and reach shoppers only on your sign-off. Nothing goes live automatically.
Tamper-evident audit log
A hash-chained, per-tenant log of administrative, publish/approve, and SSO actions — visible to your Owners and verifiable end to end.
Role-based access & isolation
Owner, Marketing, Service desk, IT and Website-owner roles, each scoped server-side. Every record is keyed to one brand; no tenant can read another's data.
Single sign-on (SSO)
Per-tenant SSO with just-in-time provisioning and role mapping, behind a signed-assertion sign-in. Native SAML/OIDC connectors are next on the same seam.
Hosted in the EU
The platform and its database run in Frankfurt; your catalogue, knowledge and transcripts are stored there. Bespoke Seb acts as a GDPR data processor, with a DPA on request.
Not used to train models
Conversation content goes to Anthropic solely to generate the reply, under API terms that exclude training. Bespoke Seb builds no cross-brand shopper profiles and sells no data.
Encrypted, no card data
TLS for all shopper, API and dashboard traffic; storage on encrypted volumes. Checkout stays on your site, so no payment-card data ever touches Bespoke Seb (PCI out of scope).
AI transparency (EU AI Act)
Shoppers are told they're speaking with an AI associate. Per-brand blocked topics and a brand-anchored boundary keep it on your world.
Where your data goes
Four hops, and no others.
- On your storefront A shopper types into the widget — one script tag, served from your own page.
- Frankfurt, EU The message reaches our API, which reads your catalogue and brand knowledge from the EU database.
- Anthropic — inference only The conversation is sent to the model to draft one reply. It is not retained for training.
- Back to Frankfurt The turn and its funnel events are written to the EU database. Your team reads them through the authenticated dashboard.
Nothing else leaves. Shopper content is not sent to advertising, analytics, or data-broker destinations, and there is no cross-brand profile of any shopper. Checkout never touches us — payment-card data stays on your site, which is why PCI DSS is out of scope rather than “compliant”.
Sub-processors
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Render | Application hosting, database, backups | EU — Frankfurt |
| Anthropic | Model inference — generating each reply | USA, under Standard Contractual Clauses. No training on API data. |
| Stripe | Merchant subscription payments (no shopper data) | EU / USA |
| Transactional email provider | Set-password and team-invite emails to your staff | EU / USA |
This is the complete list. We will give you advance notice of any addition, and the same list is maintained in our Privacy Policy and in the data-processing agreement.
Retention & erasure
You can have it back, and you can have it gone.
Every record is keyed to one brand, and the database is the single storage seam — which is what makes export and deletion a bounded operation rather than an archaeology project.
| Data | Kept for | On request |
|---|---|---|
| Catalogue & brand knowledge | Life of the account; replaced on each approved re-crawl | Exported or deleted |
| Shopper conversations & transcripts | Sessions expire automatically; stored transcripts are prunable | Deleted; a fixed retention window can be agreed in the DPA |
| Funnel & conversion events | Life of the account (pseudonymous; this is what measures the lift) | Exported or deleted |
| Your team's accounts & audit log | Life of the account, then as law requires | Exported; deleted on termination |
| Payment-card data | Never collected — checkout stays on your site | — |
A configurable, self-serve retention policy in the dashboard is on the roadmap and is not built yet; today a retention window is set contractually and applied by us. Erasure requests reaching you as controller are handled by us as your processor within the DPA's timeframe.
Compliance status
What we hold, and what we do not.
Bespoke Seb is a young company, and we would rather your reviewer read this row-by-row than discover it in diligence. Nothing below is aspirational unless it says so.
| Item | Status | Detail |
|---|---|---|
| GDPR — processor role & DPA | In place | Signed DPA with SCCs available before signature |
| EU data residency | In place | Application and database in Frankfurt; inference in the USA under SCCs |
| EU AI Act — transparency obligation | In place | Shoppers are told they are speaking with an AI. The associate is a limited-risk system: it recommends, it does not decide anything about a person. |
| Tamper-evident audit log | In place | Hash-chained, per tenant, chain-verifiable by your Owners |
| Single sign-on | Partial | Signed-assertion sign-in with just-in-time provisioning and role mapping is in place; a native SAML / OIDC connector is not built yet. |
| PCI DSS | Out of scope | No cardholder data ever reaches the platform |
| SOC 2 Type II | Not held | No report exists and no audit window has begun. We will commit to a window as part of a first enterprise engagement. |
| ISO/IEC 27001 | Not held | Not certified and not currently in certification. The controls above are the substance; the certificate is not yet the evidence. |
| Third-party penetration test | Not yet conducted | No independent test report exists. We will commission one against a pilot deployment, and will share the report and remediation. |
| Incident response & breach notification | Being formalised | We will notify you without undue delay and within GDPR's 72 hours, with a named escalation contact in the DPA. The written runbook is not finalised. |
| Cyber-insurance & MSA | On engagement | Master agreement with defined liability, mutual NDA, and cover put in place for an enterprise engagement |
If a certification is a hard gate for your procurement, tell us at the first meeting rather than the last — the honest answer today is that we would be starting the audit for you, and that timeline belongs in the pilot plan.
Talk to us
Your security team's questions, answered.
We'll share the full security brief, a data-flow walkthrough, and a DPA.
Bespoke S