Rumbe AIRumbe AI
Trust Center / Security

Security at Rumbe AI

Layered application, data, tenant, AI, widget, and operational safeguards — protecting conversations, identities, agent activity, provider credentials, and organization knowledge.

01 · Security Architecture Overview

Distinct modules, scoped controls.

Rumbe is composed of customer, agent, administration, widget, and subscription modules. Separation allows controls to be applied according to each component’s role and exposure.

01Sensitivity-aware data handling for personal and operational records
02Encryption for stored PII and provider secrets
03Secure JWT sessions and enterprise SSO support
04Role-based authorization for agents, administrators, and platform operators
05API-boundary validation and safe rendering of model output
06Tenant-aware database access and vector retrieval
07Domain-restricted widget deployment
08PHI access, agent activity, and AI transaction logging
09Redaction of recognized sensitive patterns before selected LLM requests
10Human handoff when retrieval confidence is insufficient
02 · Data Classification

Sensitivity-matched protections for every record

Rumbe can classify data according to sensitivity so protections can be matched to the risk of the record. User identities, agent identities, organization records, support conversations, tickets, attachments, and integration credentials require different handling from public configuration data.

High-sensitivity records can receive elevated safeguards such as encryption, restricted access, audit logging, reason tracking, and controlled export.

03 · Authentication & Access

JWT sessions, enterprise SSO, and role-based access

The customer portal supports JWT-based authentication using secure HTTP-only cookies. Enterprise SSO can integrate with identity providers such as Okta, Microsoft Entra ID / Azure AD, and Google Workspace through standard SAML or OAuth flows.

Role-based access control separates what customers, agents, tenant administrators, and platform administrators can view or change. Authorization guards protect routes and workflows according to assigned permissions.

04 · Encryption & Secrets

Authenticated encryption for sensitive fields and provider keys

Sensitive stored fields can be encrypted before database persistence. Provider credentials — including LLM and SMTP keys — are protected using authenticated encryption and are not intended to be displayed in plain text after storage.

A dedicated encryption key can be separated from primary database credentials, reducing the value of a database-only compromise.

05 · Tenant Isolation

Organization-scoped data and tenant-isolated retrieval

Rumbe uses organization identifiers and tenant-aware data access to separate customers. Conversations, tickets, agents, end users, settings, audit records, and knowledge sources are associated with the active organization.

The RAG layer uses tenant-specific vector collections so retrieval is scoped to the correct organization.

Your Rumbe AI assistant is designed to retrieve from your organization’s approved knowledge sources — not another tenant’s content.

06 · AI Safeguards

Redaction, citations, and confidence-based handoff

Rumbe can redact recognized sensitive patterns before content is transmitted to configured AI providers. Source-grounded retrieval and citations help users understand where an answer originated. Confidence checks can trigger a human handoff instead of forcing an uncertain automated response.

AI request hashing supports traceability while avoiding unnecessary duplicate storage of full sensitive payloads.

07 · Secure Widget

Tenant-specific keys and domain-whitelisted embedding

The Rumbe widget is compiled without client-framework dependencies, reducing dependency conflicts on host websites. Tenant-specific keys and domain whitelisting help prevent unauthorized embedding.

Authenticated widget deployments can associate a verified host-session profile with the support interaction when the Sign-In Pro capability is enabled and implemented correctly.

08 · Logging & Investigation

Audit coverage for sensitive access and AI activity

Rumbe’s documented audit model covers sensitive record access, AI transactions, and agent or administrator activity. Logs can support incident review, access accountability, troubleshooting, and operational governance.

09 · PII & PHI

Redaction, reason-tracked access, and forensic review

Rumbe’s safeguards include PII-aware schema design, neural redaction before selected AI requests, PHI access logging, and controlled handling of sensitive attachments.

10 · BYOL Keys

Bring-your-own LLM keys with encrypted, tenant-scoped storage

Customer-supplied provider credentials are stored with AES-256-GCM authenticated encryption and resolved from authenticated tenant context. Saved keys are not redisplayed in plain text.

11 · Infrastructure

Modular runtime separation and environment-specific configuration

Customer, agent, admin, widget, and billing modules run under distinct runtime configurations. Development, staging, and production use separate credentials, secrets, and allowed domains.

12 · Secure Development

Validation, safe rendering, and least-privilege configuration

Rumbe’s architecture applies validation at API boundaries, safe Markdown rendering, server-side secret validation, webhook signature verification, environment-specific configuration, and least-privilege role separation.

Security also depends on deployment practices such as key rotation, patching, dependency review, backup protection, retention management, monitoring, incident response, and secure customer configuration.

Explore the security library

All security topics

FAQ

Frequently asked questions

How does Rumbe protect stored personal data?

Documented safeguards include AES-256 encryption for sensitive fields, authenticated encryption for provider secrets, role-based access, tenant boundaries, and audit logging.

How does Rumbe prevent cross-customer AI retrieval?

Knowledge retrieval is scoped to organization-specific content and tenant-isolated vector collections.

Does Rumbe support enterprise SSO?

Yes. The product guide describes SAML or OAuth-based SSO integrations for corporate identity providers.

Does Rumbe send every conversation to an AI provider unchanged?

Rumbe documents a neural redaction layer that can detect and replace sensitive patterns before selected content is sent to configured providers. Exact coverage should be validated for the deployment.

Evaluate Rumbe AI for your environment.

Security review requirements differ by industry, deployment model, data type, and risk profile. Vovance Inc. can discuss Rumbe AI’s architecture, available controls, deployment assumptions, and contractual options for your use case.