GDPR · DPA available EU data residency AI-transparent Audit-logged

Security & data posture

An AI on your storefront that can't go off-script.

Bespoke Seb is built so a luxury house can put an AI associate in front of customers without losing control — it can't invent a product, a price, or a promise, and every sensitive action is logged. Here is exactly what's in place, and what's on the way.

Built secure by design

Trust earned by architecture, not by promise.

No hallucinated commerce

The associate can only surface pieces a live catalogue query returned in that conversation. Prices and policies come only from your systems — it cannot invent a product, a price, or a promise.

Human approval gate

Catalogue and knowledge changes are staged for review and reach shoppers only on your sign-off. Nothing goes live automatically.

Tamper-evident audit log

A hash-chained, per-tenant log of administrative, publish/approve, and SSO actions — visible to your Owners and verifiable end to end.

Role-based access & isolation

Owner, Marketing, Service desk, IT and Website-owner roles, each scoped server-side. Every record is keyed to one brand; no tenant can read another's data.

Single sign-on (SSO)

Per-tenant SSO with just-in-time provisioning and role mapping, behind a signed-assertion sign-in. Native SAML/OIDC connectors are next on the same seam.

EU data residency

Region-pinnable hosting with EU data residency available for European brands. Bespoke Seb acts as a GDPR data processor, with a DPA on request.

Not used to train models

Conversations are sent to our model provider only to generate the reply, under API terms that exclude training. Bespoke Seb builds no cross-brand shopper profiles.

Encrypted, no card data

TLS for all shopper, API and dashboard traffic; storage on encrypted volumes. Checkout stays on your site, so no payment-card data ever touches Bespoke Seb (PCI out of scope).

AI transparency (EU AI Act)

Shoppers are told they're speaking with an AI associate. Per-brand blocked topics and a brand-anchored boundary keep it on your world.

Talk to us

Your security team's questions, answered.

We'll share the full security brief, a data-flow walkthrough, and a DPA.

Contact security