Torbie
A glossy translucent 3D shield with a soft checkmark, suggesting security

Security you can verify

Torbie is built so your data stays yours. Isolation is enforced at the database level, the AI only sees what you allow, and every sensitive action is logged.

Per-business isolation

Every business's data is isolated at the database level with Postgres row-level security, FORCE-enabled and default-deny. One business can never read another's data — proven by automated tests.

Strict AI grounding

In strict mode your bot answers only from your own knowledge and refuses everything else — it can't leak, guess, or wander off-topic onto other businesses' data.

Default-deny connectors

When you connect live data, the AI only ever receives the exact fields you allowlist. Everything else is stripped before the model sees it.

Signed & rate-limited

Every connector request is HMAC-signed with your secret, time-bound, rate-limited and logged — so you can audit exactly what was accessed.

Virus-scanned uploads

Every file a visitor or agent shares is scanned with ClamAV and rejected if it fails — before it ever reaches your team.

Encryption

Secrets (API keys, connector credentials, SMTP) are encrypted at rest; all traffic is encrypted in transit over TLS.

SSRF-guarded

The website crawler and connectors refuse private/internal network addresses, so they can't be tricked into reaching internal systems.

Two-factor auth

Protect accounts with TOTP two-factor authentication, plus admin login challenges and IP allowlisting on the platform console.

Audit logs

Sensitive actions are recorded so you can see who did what, when — across your team and every connector access.

Platform safeguards

A global AI kill-switch, per-visitor rate limits and daily cost caps keep the service safe and predictable under load.

GDPR & CCPA tooling

Export or erase any customer's data on request, set retention policies, and offer a cookie-free widget mode. A DPA is available.

Data you can leave with

Export your conversations, customers and analytics to CSV anytime. Your data is never locked in.

Isolation, proven

Not a promise — enforced by design

Tenant isolation isn't a setting we hope holds. It's enforced at the database level with Postgres FORCE row-level security, so one business can never read another's data — even if the application layer is bypassed.

Operated by UNIVERSALHOMEANDTECH LTD (UK company no. 16534780, ICO registration ZC044007). For security questions or to report an issue, contact us.

Data you control, support that scales

Start free today. Your AI agent is live before your coffee gets cold.

No credit card required · 30-day trial · Cancel anytime